1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25349
scadaApp for iOS General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices.

CVE-2019-20480
Software Genérico Web
4.6
MEDIUM
EPSS
0.3%
2019 1 PoC

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.

CVE-2019-20648
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2019 1 PoC

NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.

CVE-2019-20481
Software Genérico General
4.6
MEDIUM
EPSS
0.3%
2019 1 PoC

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

CVE-2019-11287
RabbitMQ for Pivotal Platform Web
4.5
MEDIUM
EPSS
4.6%
2019 CWE-400 2 PoCs

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.

CVE-2019-3641
Threat Intelligence Exchange Server (TIE Server) Web Windows
4.5
MEDIUM
EPSS
0.2%
2019 CWE-285 1 PoC

Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.

CVE-2019-3842
systemd General
4.5
MEDIUM
EPSS
0.1%
2019 CWE-285 2 PoCs

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".

CVE-2019-3634
Data Loss Prevention (DLPe) for Windows Windows
4.4
MEDIUM
EPSS
0.0%
2019 1 PoC

Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via an encrypted message sent to DLPe which when decrypted results in DLPe reading unallocated memory.

CVE-2019-3633
Data Loss Prevention (DLPe) for Windows Windows
4.4
MEDIUM
EPSS
0.0%
2019 1 PoC

Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results in DLPe reading unallocated memory.

CVE-2019-6192
Power Management driver General
4.4
MEDIUM
EPSS
2.1%
2019 1 PoC

A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.

CVE-2019-19983
Software Genérico Web Windows
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.

CVE-2019-4556
Qradar Advisor General
4.3
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 166205.

CVE-2019-3810
moodle General
4.3
MEDIUM
EPSS
8.4%
2019 CWE-79 2 PoCs

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVE-2019-20739
Software Genérico General
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

NETGEAR R8500 devices before v1.0.2.128 are affected by a buffer overflow by an unauthenticated attacker.

CVE-2019-20654
Software Genérico General
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

CVE-2019-4084
Rational Collaborative Lifecycle Management General
4.3
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) could allow an authenticated user to obtain sensitive information from CLM Applications that could be used in further attacks against the system. IBM X-Force ID: 157384.

CVE-2019-19980
Software Genérico Web Windows
4.3
MEDIUM
EPSS
0.2%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.

CVE-2019-20746
Software Genérico Web
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by reflected XSS. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7800 before 1.0.2.58, R8900 before 1.0.4.12, R9000 before 1.0.4.8, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, WN3000RPv2 before 1.0.0.68, WN3000RPv3 before 1.0.2.70, WN3100RPv2 before 1.0.0.60, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.68.

CVE-2019-25102
simple-markdown Networking
4.3
MEDIUM
EPSS
0.2%
2019 CWE-1333 1 PoC

A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.6.1 is able to address this issue. The patch is identified as 015a719bf5cdc561feea05500ecb3274ef609cd2. It is recommended to upgrade the affected component. VDB-220638 is the identifier assigned to th

CVE-2019-4047
Jazz Reporting Service General
4.3
MEDIUM
EPSS
0.4%
2019 1 PoC

IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.