6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-20049
Software Genérico General
N/A
UNKNOWN
EPSS
25.5%
2019 2 PoCs

An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().

CVE-2019-2984
VM VirtualBox Database
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.34 and prior to 6.0.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM V

CVE-2019-3931
Crestron AirMedia Web
N/A
UNKNOWN
EPSS
2.3%
2019 CWE-88 1 PoC

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to upload files to the device and ultimately execute code as root.

CVE-2019-17008
Thunderbird General
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVE-2019-14787
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.

CVE-2019-7273
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).

CVE-2019-2813
GraalVM Enterprise Edition Database
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Vulnerability in the Oracle GraalVM Enterprise Edition component of Oracle GraalVM (subcomponent: GraalVM). The supported version that is affected is 19.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise

CVE-2019-6975
Software Genérico General
N/A
UNKNOWN
EPSS
13.5%
2019 1 PoC

Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.

CVE-2019-10475
Jenkins build-metrics Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2019 2 PoCs

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

CVE-2019-8389
Software Genérico Cloud
N/A
UNKNOWN
EPSS
5.4%
2019 1 PoC

A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).

CVE-2019-20372
Software Genérico Web
N/A
UNKNOWN
EPSS
69.3%
2019 4 PoCs

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVE-2019-13699
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-16745
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.

CVE-2019-14547
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker could inject the JavaScript inside the filename and send it to users, thus helping him steal victims' cookies (hence compromising their accounts).

CVE-2019-14960
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

CVE-2019-19947
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.

CVE-2019-19699
Software Genérico Web
N/A
UNKNOWN
EPSS
8.9%
2019 1 PoC

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via a

CVE-2019-19595
Software Genérico Web
N/A
UNKNOWN
EPSS
5.6%
2019 1 PoC

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

CVE-2019-6112
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2019 1 PoC

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

CVE-2019-2825
Applications Manager Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Ap