6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-7481
🔥 KEV SMA100 Networking ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2019 CWE-89 0 PoCs

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVE-2019-3622
Data Loss Prevention (DLPe) for Windows Windows
7.5
HIGH
EPSS
0.1%
2019 CWE-552 1 PoC

Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.

CVE-2019-9514
Software Genérico Web
7.5
HIGH
EPSS
9.5%
2019 CWE-400 3 PoCs

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

CVE-2019-0028
Junos OS Networking
7.5
HIGH
EPSS
0.6%
2019 CWE-404 1 PoC

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process to crash and restart. By simulating a specific BGP session restart, an attacker can repeatedly crash the RPD process causing prolonged denial of service (DoS). Graceful restart helper mode for BGP is enabled by default. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos

CVE-2019-0752
🔥 KEV Internet Explorer 11 General
7.5
HIGH
EPSS
91.8%
2019 3 PoCs

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.

CVE-2019-1621
Cisco Data Center Network Manager Networking
7.5
HIGH
EPSS
60.2%
2019 CWE-264 4 PoCs

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker could exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.

CVE-2019-1367
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
90.7%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

CVE-2019-1429
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
83.0%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

CVE-2019-3636
McAfee Total Protection Windows
7.5
HIGH
EPSS
0.1%
2019 1 PoC

A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.

CVE-2019-9517
Software Genérico Web
7.5
HIGH
EPSS
4.6%
2019 CWE-400 4 PoCs

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

CVE-2019-5091
LEADTOOLS libltdic.so General
7.5
HIGH
EPSS
0.4%
2019 CWE-835 1 PoC

An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause an infinite loop, resulting in a denial of service. An attacker can send a packet to trigger this vulnerability.

CVE-2019-9518
Software Genérico Web
7.5
HIGH
EPSS
3.6%
2019 CWE-400 3 PoCs

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.

CVE-2019-8394
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
87.5%
2019 1 PoC

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

CVE-2019-5038
Nest Labs General
7.5
HIGH
EPSS
1.1%
2019 CWE-121 1 PoC

An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.

CVE-2019-16638
Software Genérico General
7.5
HIGH
EPSS
0.1%
2019 1 PoC

An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1.

CVE-2019-5747
Software Genérico General
7.5
HIGH
EPSS
0.4%
2019 3 PoCs

An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to assurance of a 4-byte length when decoding DHCP_SUBNET. NOTE: this issue exists because of an incomplete fix for CVE-2018-20679.

CVE-2019-9564
Cam Pan v2 General
7.5
HIGH
EPSS
0.4%
2019 1 PoC

A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

CVE-2019-25053
Software Genérico General
7.5
HIGH
EPSS
0.8%
2019 1 PoC

A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of the web tree via a crafted URL.

CVE-2019-20360
Software Genérico Web Windows
7.5
HIGH
EPSS
1.7%
2019 1 PoC

A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and the token is set to the corresponding MD5 hash of the meta key selected, one can make a request to the restricted endpoints, and thus access sensitive donor data.

CVE-2019-9513
Software Genérico Web
7.5
HIGH
EPSS
6.7%
2019 CWE-400 5 PoCs

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.