3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-12990
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2019 1 PoC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

CVE-2019-3912
LabKey Server Community Edition General ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2019 CWE-601 1 PoC

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

CVE-2019-12461
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.8%
2019 1 PoC

Web Port 1.19.1 allows XSS via the /log type parameter.

CVE-2019-16097
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2019 6 PoCs

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVE-2019-16996
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2019 0 PoCs

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.

CVE-2019-17662
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2019 11 PoCs

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

CVE-2019-17506
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2019 0 PoCs

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

CVE-2019-18394
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2019 0 PoCs

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

CVE-2019-2579
WebCenter Sites Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
69.4%
2019 1 PoC

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-3799
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2019 CWE-22 2 PoCs

Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2019-11886
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
22.1%
2019 3 PoCs

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

CVE-2019-17538
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2019 0 PoCs

Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.

CVE-2019-19824
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2019 3 PoCs

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

CVE-2019-7315
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2019 1 PoC

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

CVE-2019-5434
Revive Adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.1%
2019 CWE-502 1 PoC

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.

CVE-2019-1010287
Timesheet Next Gen Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2019 0 PoCs

Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.

CVE-2019-8449
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2019 3 PoCs

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

CVE-2019-6799
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
76.6%
2019 0 PoCs

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVE-2019-16123
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.7%
2019 1 PoC

In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.