6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-7427
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2019 2 PoCs

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.

CVE-2019-11831
Software Genérico General
N/A
UNKNOWN
EPSS
9.5%
2019 1 PoC

The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

CVE-2019-20382
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 2 PoCs

QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.

CVE-2019-16223
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
4.3%
2019 3 PoCs

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVE-2019-1010163
Photo 2 Video Converter General
N/A
UNKNOWN
EPSS
0.2%
2019 3 PoCs

Socusoft Co Photo 2 Video Converter 8.0.0 is affected by: Buffer Overflow - Local shell-code execution and Denial of Service. The impact is: Local privilege escalation (dependant upon conditions), shell code execution and denial-of-service. The component is: pdmlog.dll library. The attack vector is: The attacker must have access to local system (either directly, or remotley).

CVE-2019-9881
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2019 3 PoCs

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

CVE-2019-9966
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.

CVE-2019-0539
Microsoft Edge General
N/A
UNKNOWN
EPSS
91.0%
2019 4 PoCs

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0567, CVE-2019-0568.

CVE-2019-6735
Reader General
N/A
UNKNOWN
EPSS
0.9%
2019 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7355.

CVE-2019-13005
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Enterprise Edition and Community Edition 1.10 through 12.0.2. The GitLab graphql service was vulnerable to multiple authorization issues that disclosed restricted user, group, and repository metadata to unauthorized users. It has Incorrect Access Control.

CVE-2019-5916
POWER EGG General
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier) allows remote attackers to execute EL expression on the server via unspecified vectors.

CVE-2019-17652
Fortinet FortiClientLinux Networking
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched process due the argv data not been well sanitized.

CVE-2019-7617
Elastic APM agent for Python General
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-20 1 PoC

When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.

CVE-2019-1010258
nanosvg General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

nanosvg library nanosvg after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726 is affected by: Buffer Overflow. The impact is: Memory corruption leading to at least DoS. More severe impact vectors need more investigation. The component is: it's part of a svg processing library. function nsvg__parseColorRGB in src/nanosvg.h / line 1227. The attack vector is: It depends library usage. If input is passed from the network, then network connectivity is enough. Most likely an attack will require opening a specially crafted .svg file.

CVE-2019-18954
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.

CVE-2019-9325
Android General
N/A
UNKNOWN
EPSS
8.9%
2019 1 PoC

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302

CVE-2019-13498
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

CVE-2019-7771
Adobe Acrobat and Reader General
N/A
UNKNOWN
EPSS
2.9%
2019 1 PoC

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVE-2019-14364
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.

CVE-2019-9861
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 4 PoCs

Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way.