6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-19002
eSOMS Web
6.3
MEDIUM
EPSS
0.3%
2019 CWE-16 1 PoC

For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

CVE-2019-20703
Software Genérico General
6.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

CVE-2019-4680
Sterling B2B Integrator Database
6.3
MEDIUM
EPSS
0.5%
2019 1 PoC

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171733.

CVE-2019-11212
TIBCO MDM Web
6.3
MEDIUM
EPSS
0.2%
2019 1 PoC

The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.

CVE-2019-4650
Maximo Asset Management Database
6.3
MEDIUM
EPSS
0.6%
2019 1 PoC

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

CVE-2019-11849
Software Genérico Web
6.3
MEDIUM
EPSS
0.0%
2019 1 PoC

A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.

CVE-2019-25071
iOS General
6.3
MEDIUM
EPSS
0.7%
2019 CWE-269 1 PoC

A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit details have been disclosed to the public. The existence and implications of this vulnerability are doubted by Apple even though multiple public videos demonstrating the attack exist. Upgrading to version 13.0 migt be able to address this issue. It is recommended to upgrade affected devices. NOTE: Apple claims, that after exa

CVE-2019-20740
Software Genérico General
6.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R7300 before 1.0.0.70, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

CVE-2019-25065
OpenNetAdmin General
6.3
MEDIUM
EPSS
73.7%
2019 CWE-78 3 PoCs

A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2019-11484
whoopsie General
6.3
MEDIUM
EPSS
0.1%
2019 CWE-190 1 PoC

Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.

CVE-2019-3900
Kernel General
6.3
MEDIUM
EPSS
0.2%
2019 CWE-835 5 PoCs

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.

CVE-2019-11850
Software Genérico General
6.3
MEDIUM
EPSS
0.0%
2019 1 PoC

A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution

CVE-2019-19984
Software Genérico Web Windows
6.3
MEDIUM
EPSS
0.2%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.

CVE-2019-3849
moodle General
6.3
MEDIUM
EPSS
0.4%
2019 CWE-285 1 PoC

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

CVE-2019-2853
Text Web Database
6.3
MEDIUM
EPSS
0.6%
2019 2 PoCs

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a p

CVE-2019-20705
Software Genérico General
6.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

CVE-2019-0986
Windows 10 Version 1703 Windows
6.3
MEDIUM
EPSS
2.3%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete files or folders of their choosing. The security update addresses the vulnerability by correcting how the Windows User Profile Service handles symlinks.

CVE-2019-25067
Podman Web
6.3
MEDIUM
EPSS
0.8%
2019 2 PoCs

A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-143949 was assigned to this vulnerability.

CVE-2019-10181
icedtea-web General
6.3
MEDIUM
EPSS
0.4%
2019 CWE-345 2 PoCs

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVE-2019-25066
ajenti Web Networking
6.3
MEDIUM
EPSS
77.6%
2019 CWE-269 2 PoCs

A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.32 is able to address this issue. The name of the patch is 7aa146b724e0e20cfee2c71ca78fafbf53a8767c. It is recommended to upgrade the affected component.