794 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-17390
Software Genérico General
8.2
HIGH
EPSS
0.1%
2019 1 PoC

An issue was discovered in the Outlook add-in in Pronestor Planner before 8.1.77. There is local privilege escalation in the Health Monitor service because PronestorHealthMonitor.exe access control is mishandled, aka PNB-2359.

CVE-2019-5093
LEADTOOLS libltdic.so General
8.1
HIGH
EPSS
0.3%
2019 CWE-190 1 PoC

An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an integer overflow, resulting in heap corruption. An attacker can send a packet to trigger this vulnerability.

CVE-2019-3638
Web Gateway(MWG) General
8.1
HIGH
EPSS
1.0%
2019 1 PoC

Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.

CVE-2019-1579
🔥 KEV Palo Alto Networks GlobalProtect Portal/Gateway Interface Networking
8.1
HIGH
EPSS
92.9%
2019 3 PoCs

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

CVE-2019-5018
Sqlite3 Database
8.1
HIGH
EPSS
2.7%
2019 CWE-416 2 PoCs

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

CVE-2019-3766
Elastic Cloud Storage Cloud
8.1
HIGH
EPSS
2.0%
2019 CWE-307 1 PoC

Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targeted accounts.

CVE-2019-11855
Software Genérico General
8.1
HIGH
EPSS
0.0%
2019 1 PoC

An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

CVE-2019-19826
Software Genérico Web
8.1
HIGH
EPSS
1.5%
2019 1 PoC

The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.

CVE-2019-17337
TIBCO Spotfire Analytics Platform for AWS Marketplace Web Cloud
8.1
HIGH
EPSS
0.3%
2019 1 PoC

The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflected cross-site scripting (XSS) attack. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0 and TIBCO Spotfire Server: versions 7.11.7 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.3.2, 10.3.3, and 10.3.4, versions 10.4.0, 10.5.0, and 10.6.0.

CVE-2019-6340
🔥 KEV Drupal Core Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2019 12 PoCs

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you sho

CVE-2019-20651
Software Genérico General
8.1
HIGH
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16.

CVE-2019-18568
Antivirus Free Antivirus General
8.1
HIGH
EPSS
0.1%
2019 CWE-680 1 PoC

Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.

CVE-2019-11862
Software Genérico Networking
8.1
HIGH
EPSS
0.0%
2019 1 PoC

The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.

CVE-2019-5144
Kakadu Software General
8.1
HIGH
EPSS
3.2%
2019 CWE-191 1 PoC

An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file to the victim to trigger this vulnerability.

CVE-2019-3661
Advanced Threat Defense (ATD) Database
8.1
HIGH
EPSS
0.2%
2019 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.

CVE-2019-9579
Software Genérico Windows
8.1
HIGH
EPSS
0.7%
2019 1 PoC

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

CVE-2019-11542
Software Genérico General
8.0
HIGH
EPSS
34.7%
2019 1 PoC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVE-2019-17333
TIBCO EBX Web
8.0
HIGH
EPSS
0.4%
2019 1 PoC

The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.1.fixS and below, versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, and 5.9.7.

CVE-2019-5130
Foxit Web
8.0
HIGH
EPSS
3.9%
2019 CWE-416 1 PoC

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.7.0.29435. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVE-2019-3631
McAfee Enterprise Security Manager (ESM) General
8.0
HIGH
EPSS
2.8%
2019 1 PoC

Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.