6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-7629
Software Genérico General
N/A
UNKNOWN
EPSS
5.9%
2019 1 PoC

Stack-based buffer overflow in the strip_vt102_codes function in TinTin++ 2.01.6 and WinTin++ 2.01.6 allows remote attackers to execute arbitrary code by sending a long message to the client.

CVE-2019-19742
Software Genérico Web
N/A
UNKNOWN
EPSS
3.7%
2019 3 PoCs

On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.

CVE-2019-20612
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Broadcom Wi-Fi, and SEC Wi-Fi chipsets) software. Wi-Fi allows a denial of service via TCP SYN packets. The Samsung ID is SVE-2018-13162 (March 2019).

CVE-2019-19447
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2019 2 PoCs

In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

CVE-2019-6789
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

CVE-2019-12148
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into the device's admin web portal without providing any credentials. This affects /var/webconfig/gui/Webconfig.inc.php.

CVE-2019-9915
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.0%
2019 0 PoCs

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVE-2019-12299
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section.

CVE-2019-13718
Chrome General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVE-2019-9055
Software Genérico Web
N/A
UNKNOWN
EPSS
32.0%
2019 1 PoC

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVE-2019-20908
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 4 PoCs

An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

CVE-2019-13374
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

CVE-2019-11660
Data Protector General
N/A
UNKNOWN
EPSS
34.2%
2019 1 PoC

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVE-2019-15929
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.

CVE-2019-10788
im-metadata General
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.

CVE-2019-2994
Marketing Web Database
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all

CVE-2019-12880
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.

CVE-2019-3968
OpenEMR General
N/A
UNKNOWN
EPSS
53.6%
2019 1 PoC

In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.

CVE-2019-5369
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-17647
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.