212 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-0192
Apache Solr Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2019 4 PoCs

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

CVE-2019-7543
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2019 0 PoCs

In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.

CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVE-2019-14750
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2019 2 PoCs

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

CVE-2019-17228
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2019 1 PoC

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

CVE-2019-13101
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2019 1 PoC

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.

CVE-2019-12962
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2019 1 PoC

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

CVE-2019-12593
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.7%
2019 1 PoC

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

CVE-2019-17232
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVE-2019-14950
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 0 PoCs

The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

CVE-2019-20224
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2019 2 PoCs

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

CVE-2019-12276
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2019 1 PoC

A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.

CVE-2019-20933
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2019 3 PoCs

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

CVE-2019-2588
BI Publisher (formerly XML Publisher) Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2019 1 PoC

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector:

CVE-2019-6793
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2019 2 PoCs

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVE-2019-14322
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.1%
2019 3 PoCs

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

CVE-2019-1010290
Babel Web ⚡ nuclei
N/A
UNKNOWN
EPSS
24.4%
2019 1 PoC

Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.

CVE-2019-11013
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2019 2 PoCs

Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.

CVE-2019-15642
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2019 1 PoC

rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."

CVE-2019-16997
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2019 0 PoCs

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.