6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-9801
Thunderbird Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVE-2019-20852
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).

CVE-2019-8352
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2019 1 PoC

By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.

CVE-2019-11636
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.

CVE-2019-16872
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

CVE-2019-14486
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

GnuCOBOL 2.2 has a buffer overflow in cb_evaluate_expr in cobc/field.c via crafted COBOL source code.

CVE-2019-13375
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.8%
2019 2 PoCs

A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.

CVE-2019-3914
Fios Quantum Gateway (G1100) General
N/A
UNKNOWN
EPSS
18.0%
2019 1 PoC

Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.

CVE-2019-17598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.

CVE-2019-14230
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
6.6%
2019 2 PoCs

An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.

CVE-2019-14293
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.

CVE-2019-18200
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 3 PoCs

An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, they are prone to keystroke injection attacks.

CVE-2019-20041
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript&colon; substring.

CVE-2019-12271
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.

CVE-2019-17600
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.

CVE-2019-16521
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product.

CVE-2019-20202
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block that was not allocated, leading to an invalid free and segmentation fault.

CVE-2019-5414
kill-port General
N/A
UNKNOWN
EPSS
0.5%
2019 CWE-77 2 PoCs

If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.

CVE-2019-5074
WAGO PFC200 General
N/A
UNKNOWN
EPSS
2.3%
2019 1 PoC

An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

CVE-2019-9844
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.