794 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25229
Xperience General
8.7
HIGH
EPSS
0.1%
2019 CWE-434 1 PoC

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

CVE-2019-25613
Easy Chat General
8.7
HIGH
EPSS
0.4%
2019 CWE-940 1 PoC

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.

CVE-2019-25355
gSOAP Web
8.7
HIGH
EPSS
0.5%
2019 CWE-22 1 PoC

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences.

CVE-2019-25480
ARMBot Web
8.7
HIGH
EPSS
0.1%
2019 CWE-22 1 PoC

ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.

CVE-2019-25560
Lyric Video Creator General
8.7
HIGH
EPSS
0.1%
2019 CWE-226 1 PoC

Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.

CVE-2019-25257
LogicalDOC Enterprise General
8.7
HIGH
EPSS
0.1%
2019 CWE-426 2 PoCs

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

CVE-2019-25240
DVR General
8.7
HIGH
EPSS
0.1%
2019 CWE-306 2 PoCs

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

CVE-2019-25401
MP-4200 General
8.7
HIGH
EPSS
0.2%
2019 CWE-400 1 PoC

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page. Remote attackers can send crafted POST requests with malformed 'admin' and 'person' parameters to crash the printer's web service, causing a denial of service condition.

CVE-2019-25239
GPON/EPON OLT Platform Web
8.7
HIGH
EPSS
0.1%
2019 CWE-552 2 PoCs

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

CVE-2019-25236
Hybrid DVR WH-H4 General
8.7
HIGH
EPSS
0.1%
2019 CWE-306 2 PoCs

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.

CVE-2019-25515
Hazir Haber Sitesi Scripti Web Database
8.7
HIGH
EPSS
0.9%
2019 CWE-89 1 PoC

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated attackers to gain administrative access by submitting crafted SQL syntax. Attackers can bypass authentication by submitting equals signs and 'or' operators as username and password parameters to access the administration panel without valid credentials.

CVE-2019-25478
GetGo Download Manager Web
8.7
HIGH
EPSS
0.1%
2019 CWE-787 1 PoC

GetGo Download Manager 6.2.2.3300 contains a buffer overflow vulnerability that allows remote attackers to cause denial of service by sending HTTP responses with excessively long headers. Attackers can craft malicious HTTP responses with oversized header values to crash the application and make it unavailable.

CVE-2019-25352
Crystal Live HTTP Server Web Windows
8.7
HIGH
EPSS
0.6%
2019 CWE-22 1 PoC

Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.

CVE-2019-25671
VA MAX Web
8.7
HIGH
EPSS
0.5%
2019 CWE-22 1 PoC

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to execute commands as the apache user.

CVE-2019-25605
EquityPandit General
8.7
HIGH
EPSS
0.0%
2019 CWE-612 1 PoC

EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.

CVE-2019-25686
Core FTP General
8.7
HIGH
EPSS
0.2%
2019 CWE-306 1 PoC

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

CVE-2019-25249
dLAN 550 duo+ Starter Kit General
8.7
HIGH
EPSS
0.2%
2019 CWE-266 2 PoCs

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.

CVE-2019-25630
PhreeBooks ERP Web
8.7
HIGH
EPSS
0.8%
2019 CWE-434 1 PoC

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

CVE-2019-25673
Laravel File Manager Web
8.7
HIGH
EPSS
0.1%
2019 CWE-434 1 PoC

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

CVE-2019-25579
phpTransformer Web
8.7
HIGH
EPSS
3.1%
2019 CWE-22 1 PoC

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.