3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-17671
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2019 2 PoCs

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVE-2019-16525
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.8%
2019 2 PoCs

An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.

CVE-2019-18957
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.1%
2019 1 PoC

Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.

CVE-2019-17231
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2019 0 PoCs

includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.

CVE-2019-20504
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.8%
2019 0 PoCs

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.

CVE-2019-7219
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2019 1 PoC

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

CVE-2019-9912
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2019 2 PoCs

The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.

CVE-2019-7254
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2019 1 PoC

Linear eMerge E3-Series devices allow File Inclusion.

CVE-2019-15858
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.2%
2019 3 PoCs

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

CVE-2019-10475
Jenkins build-metrics Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2019 2 PoCs

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

CVE-2019-6112
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2019 1 PoC

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

CVE-2019-19908
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.9%
2019 1 PoC

phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.

CVE-2019-9194
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2019 3 PoCs

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

CVE-2019-12581
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
35.8%
2019 1 PoC

A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.

CVE-2019-12583
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
59.1%
2019 1 PoC

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

CVE-2019-18952
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.7%
2019 1 PoC

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

CVE-2019-3403
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.8%
2019 CWE-863 1 PoC

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVE-2019-9879
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.2%
2019 3 PoCs

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

CVE-2019-14530
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.0%
2019 4 PoCs

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

CVE-2019-19822
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
54.1%
2019 3 PoCs

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; H