6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-17638
Eclipse Jetty Web
N/A
UNKNOWN
EPSS
30.9%
2019 CWE-672 3 PoCs

In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the pool and while thread1 is about to use the ByteBuffer to write response1 data, thread2 fills the ByteBuffer with other data. Thread1 then proceeds to write the buffer that now contains different data. This results in client1, which issued

CVE-2019-14371
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

CVE-2019-2876
VM VirtualBox Database
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N

CVE-2019-18909
ThinPro Linux Networking
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.

CVE-2019-10078
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
3.0%
2019 2 PoCs

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

CVE-2019-16069
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through the SNMP protocol.

CVE-2019-19576
Software Genérico Web
N/A
UNKNOWN
EPSS
50.6%
2019 4 PoCs

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

CVE-2019-7176
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVE-2019-8268
UltraVNC General
N/A
UNKNOWN
EPSS
1.4%
2019 CWE-193 1 PoC

UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString function, which can potentially result code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1207.

CVE-2019-19614
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1.

CVE-2019-2681
MySQL Server Database
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2019-15771
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVE-2019-9172
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

CVE-2019-6333
Touchpoint Analytics General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system service.

CVE-2019-13505
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.

CVE-2019-13291
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.

CVE-2019-13575
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

CVE-2019-16517
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.

CVE-2019-14478
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript code in the context of the user's browser if the victim opens or searches for a node whose "Display Name" contains an XSS payload.

CVE-2019-16072
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.3%
2019 1 PoC

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.