133 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-11857
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2019 1 PoC

Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.

CVE-2019-25278
FaceSentry Access Control System Web
9.1
CRITICAL
EPSS
0.1%
2019 CWE-319 1 PoC

FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication.

CVE-2019-1912
Cisco Small Business 220 Series Smart Plus Switches Web Networking
9.1
CRITICAL
EPSS
12.2%
2019 CWE-285 1 PoC

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to modify the configuration of an affected device or

CVE-2019-20457
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2019 1 PoC

An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorization cookie. The value of the authorization cookie is the MD5 hash of the password in hexadecimal. An attacker can easily derive the true MD5 hash from this, and use offline cracking attacks to obtain administrative access to the device.

CVE-2019-25211
Software Genérico Web
9.1
CRITICAL
EPSS
0.4%
2019 4 PoCs

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.

CVE-2019-14418
Software Genérico General
9.1
CRITICAL
EPSS
3.7%
2019 1 PoC

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.

CVE-2019-5090
LEADTOOLS libltdic.so General
9.1
CRITICAL
EPSS
0.3%
2019 CWE-125 1 PoC

An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an out-of-bounds read, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.

CVE-2019-4013
BigFix Platform General
9.0
CRITICAL
EPSS
16.1%
2019 1 PoC

IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.

CVE-2019-12739
Software Genérico Web Cloud
9.0
CRITICAL
EPSS
1.4%
2019 1 PoC

lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).

CVE-2019-5035
Nest Labs General
9.0
CRITICAL
EPSS
0.5%
2019 CWE-307 1 PoC

An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this vulnerability.

CVE-2019-19915
Software Genérico Web Windows
9.0
CRITICAL
EPSS
0.2%
2019 1 PoC

The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a loss of site availability, malicious redirects, and user infections. This could also be exploited via CSRF.

CVE-2019-5015
Pixar Renderman General
9.0
CRITICAL
EPSS
0.0%
2019 CWE-749 1 PoC

A local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user with local access can use this vulnerability to escalate their privileges to root. An attacker would need local access to the machine for a successful exploit.