6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-14737
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.

CVE-2019-11515
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary files.

CVE-2019-20854
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (client-side application crash) via a LaTeX message.

CVE-2019-15682
RDesktop General
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-125 1 PoC

RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. These issues have been fixed in version 1.8.5

CVE-2019-10717
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.2%
2019 1 PoC

BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.

CVE-2019-17424
Software Genérico Networking
N/A
UNKNOWN
EPSS
28.4%
2019 3 PoCs

A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.

CVE-2019-16411
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a memory region that is not allocated. There is a check for o->len < 5 (corresponding to 2 bytes of header and 3 bytes of data). Then, "flag = *(o->data + 3)" places one beyond the 3 bytes, because the code should have been "flag = *(o->data + 1)" instead.

CVE-2019-6275
Software Genérico General
N/A
UNKNOWN
EPSS
5.3%
2019 2 PoCs

Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

CVE-2019-15940
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Victure PC530 devices allow unauthenticated TELNET access as root.

CVE-2019-11213
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2019 3 PoCs

In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure Desktop 5.3R7 and Pulse Desktop Client 9.x before Secure Desktop 9.0R3. It also affects (for Network Connect customers) Pulse Connect Secure 8.1 before 8.1R14, 8.3 before 8.3R7, and 9.0 before 9.0R3.

CVE-2019-9200
Software Genérico General
N/A
UNKNOWN
EPSS
5.3%
2019 2 PoCs

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-20203
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.

CVE-2019-6975
Software Genérico General
N/A
UNKNOWN
EPSS
13.5%
2019 1 PoC

Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.

CVE-2019-10475
Jenkins build-metrics Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2019 2 PoCs

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

CVE-2019-8389
Software Genérico Cloud
N/A
UNKNOWN
EPSS
5.4%
2019 1 PoC

A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).

CVE-2019-20372
Software Genérico Web
N/A
UNKNOWN
EPSS
69.3%
2019 4 PoCs

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVE-2019-13699
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-16745
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.

CVE-2019-14547
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker could inject the JavaScript inside the filename and send it to users, thus helping him steal victims' cookies (hence compromising their accounts).

CVE-2019-14960
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.