6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-10012
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer.

CVE-2019-16274
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

CVE-2019-3911
LabKey Server Community Edition Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2019 CWE-79 1 PoC

Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.

CVE-2019-20879
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.

CVE-2019-7391
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2019 3 PoCs

ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

CVE-2019-5679
SHIELD TV General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges

CVE-2019-9580
Software Genérico Web
N/A
UNKNOWN
EPSS
10.4%
2019 1 PoC

In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

CVE-2019-19786
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.

CVE-2019-19951
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

CVE-2019-19769
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).

CVE-2019-18370
Software Genérico Web
N/A
UNKNOWN
EPSS
64.0%
2019 1 PoC

An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

CVE-2019-16285
ThinPro Linux General
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.

CVE-2019-10750
deeply General
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.

CVE-2019-13233
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 4 PoCs

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVE-2019-3962
Nessus General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to inject arbitrary text into the feed status, which will remain saved post session expiration.

CVE-2019-14763
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.

CVE-2019-9073
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c.

CVE-2019-19311
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

CVE-2019-15782
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.

CVE-2019-8943
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2019 6 PoCs

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.