212 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-9879
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.2%
2019 3 PoCs

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

CVE-2019-10092
Apache HTTP Server Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.4%
2019 7 PoCs

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

CVE-2019-14530
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.0%
2019 4 PoCs

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

CVE-2019-19822
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
54.1%
2019 3 PoCs

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; H

CVE-2019-8903
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.3%
2019 1 PoC

index.js in Total.js Platform before 3.2.3 allows path traversal.

CVE-2019-15501
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2019 2 PoCs

Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

CVE-2019-11869
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.4%
2019 4 PoCs

The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.

CVE-2019-14205
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2019 2 PoCs

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-10232
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2019 0 PoCs

Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

CVE-2019-12988
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2019 1 PoC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

CVE-2019-8390
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2019 2 PoCs

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

CVE-2019-15859
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2019 1 PoC

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

CVE-2019-17270
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2019 2 PoCs

Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.

CVE-2019-14696
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.6%
2019 1 PoC

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

CVE-2019-7139
Magento Open Source Database ⚡ nuclei
N/A
UNKNOWN
EPSS
60.1%
2019 1 PoC

An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

CVE-2019-2578
WebCenter Sites Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2019 1 PoC

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.6 (Confidential

CVE-2019-19134
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2019 1 PoC

The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.

CVE-2019-9881
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2019 3 PoCs

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

CVE-2019-14789
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.