6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-9540
Automated Message Handling System Web
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-79 1 PoC

: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

CVE-2019-15604
Node General
N/A
UNKNOWN
EPSS
3.5%
2019 CWE-295 4 PoCs

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

CVE-2019-14496
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.

CVE-2019-14799
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.2%
2019 2 PoCs

The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

CVE-2019-1547
OpenSSL General
N/A
UNKNOWN
EPSS
0.3%
2019 9 PoCs

Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would

CVE-2019-20582
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos9810 chipsets) software. There is a use after free in the ion driver. The Samsung ID is SVE-2019-14837 (August 2019).

CVE-2019-13292
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.9%
2019 3 PoCs

A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

CVE-2019-19200
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2019 2 PoCs

REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.

CVE-2019-13396
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.6%
2019 2 PoCs

FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

CVE-2019-20211
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 7 PoCs

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website.

CVE-2019-19035
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.

CVE-2019-5487
GitLab EE DevOps Database
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-284 1 PoC

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVE-2019-12911
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.

CVE-2019-18184
Software Genérico General
N/A
UNKNOWN
EPSS
21.4%
2019 1 PoC

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

CVE-2019-15657
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.

CVE-2019-17023
Firefox General
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVE-2019-14089
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, Nicobar, QCS404, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

CVE-2019-15913
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.

CVE-2019-15393
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ZenFone Live Android device with a build fingerprint of asus/WW_Phone/ASUS_X00LD_3:7.1.1/NMF26F/14.0400.1806.203-20180720:user/release-keys contains a pre-installed app with a package name of com.asus.atd.smmitest app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.

CVE-2019-15925
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.