6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-13376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

CVE-2019-0177
Open Cloud Integrity Technology and OpenAttestation Cloud
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-19912
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

CVE-2019-13648
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user can cause a denial of service (TM Bad Thing exception and system crash) via a sigreturn() system call that sends a crafted signal frame. This affects arch/powerpc/kernel/signal_32.c and arch/powerpc/kernel/signal_64.c.

CVE-2019-19948
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

CVE-2019-15653
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and password. The username are password values are a double md5 of the plaintext real value, i.e., md5(md5(value)).

CVE-2019-12577
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file creation mask (umask) is not reset, the umask value is inherited from the calling process. This value can be manipulated to cause the privileged binary to create files with world writable permissions. A local unprivileged user can modify /tmp/pia_upscript.sh during the connect proces

CVE-2019-5479
larvitbase-api Web
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-98 2 PoCs

An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).

CVE-2019-19816
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2019 2 PoCs

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.

CVE-2019-18653
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.

CVE-2019-19447
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2019 2 PoCs

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

CVE-2019-6789
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

CVE-2019-12148
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into the device's admin web portal without providing any credentials. This affects /var/webconfig/gui/Webconfig.inc.php.

CVE-2019-9915
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.0%
2019 0 PoCs

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVE-2019-9055
Software Genérico Web
N/A
UNKNOWN
EPSS
32.0%
2019 1 PoC

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVE-2019-20908
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 4 PoCs

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

CVE-2019-13374
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

CVE-2019-11660
Data Protector General
N/A
UNKNOWN
EPSS
34.2%
2019 1 PoC

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVE-2019-15929
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.