1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-1854
Cisco Expressway Web Networking
4.1
MEDIUM
EPSS
0.0%
2019 CWE-22 3 PoCs

A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to bypass security restrictions and access the web interface of a Cisco Unified Communications Manager associated with the affected device. Valid credentials would still be required to

CVE-2019-4572
FileNet Content Manager General
4.1
MEDIUM
EPSS
0.1%
2019 1 PoC

IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798.

CVE-2019-3637
McAfee FRP General
4.1
MEDIUM
EPSS
0.0%
2019 CWE-264 1 PoC

Privilege Escalation vulnerability in McAfee FRP 5.x prior to 5.1.0.209 allows local users to gain elevated privileges via running McAfee Tray with elevated privileges.

CVE-2019-11848
Software Genérico Web
4.1
MEDIUM
EPSS
0.0%
2019 1 PoC

An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.

CVE-2019-5102
OpenWRT General
4.0
MEDIUM
EPSS
0.2%
2019 CWE-295 1 PoC

An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server

CVE-2019-5101
OpenWRT General
4.0
MEDIUM
EPSS
0.2%
2019 CWE-295 1 PoC

An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server