6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-12453
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.

CVE-2019-19937
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

CVE-2019-10310
Jenkins Ansible Tower Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins