6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-19095
eSOMS Web
5.4
MEDIUM
EPSS
0.3%
2019 CWE-20 1 PoC

Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.

CVE-2019-4149
Business Automation Workflow Web
5.4
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158415.

CVE-2019-20693
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2019 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

CVE-2019-19981
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.1%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

CVE-2019-4426
Business Automation Workflow Web
5.4
MEDIUM
EPSS
0.4%
2019 1 PoC

The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162772.

CVE-2019-4250
Rational Collaborative Lifecycle Management Web
5.4
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159648.

CVE-2019-4249
Rational Collaborative Lifecycle Management Web
5.4
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159647.

CVE-2019-4083
Rational Collaborative Lifecycle Management Web
5.4
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157383.

CVE-2019-9919
Software Genérico Web
5.4
MEDIUM
EPSS
0.3%
2019 1 PoC

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.

CVE-2019-1010023
glibc General
5.4
MEDIUM
EPSS
0.3%
2019 1 PoC

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

CVE-2019-15253
Cisco Digital Network Architecture Center (DNA Center) Web Networking
5.4
MEDIUM
EPSS
0.6%
2019 CWE-79 1 PoC

A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the contex

CVE-2019-14902
samba General
5.4
MEDIUM
EPSS
3.5%
2019 CWE-284 1 PoC

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

CVE-2019-3761
RSA Identity Governance and Lifecycle Web
5.4
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a stored cross-site scripting vulnerability in the Access Request module. A remote authenticated malicious user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the stored malicious code would gets executed by the web browser in the context of the vulnerable web application.

CVE-2019-15999
Cisco Data Center Network Manager Networking
5.4
MEDIUM
EPSS
3.2%
2019 CWE-284 2 PoCs

A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by authenticating with a specific low-privilege account. A successful exploit could allow the attacker to gain unauthorized access to the JBoss EAP, which should be limited to internal system accounts.

CVE-2019-1759
Cisco IOS XE Software Networking
5.3
MEDIUM
EPSS
28.5%
2019 CWE-284 1 PoC

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16.1.1 Release, which prevents the ACL from working when applied against the management interface. An attacker could exploit this issue by attempting to access the device via the management interface.

CVE-2019-14855
gnupg2 General
5.3
MEDIUM
EPSS
0.3%
2019 CWE-326 1 PoC

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

CVE-2019-1898
Cisco RV130W Wireless-N Multifunction VPN Router Firmware Web Networking ⚡ nuclei
5.3
MEDIUM
EPSS
78.7%
2019 CWE-285 1 PoC

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for the syslog file. A successful exploit could allow the attacker to access the information contained in the file.

CVE-2019-9103
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker can access sensitive information (e.g., conduct username disclosure attacks) on the built-in WEB-service without authorization.

CVE-2019-20462
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2019 1 PoC

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password of the Wi-Fi access point that the device used.

CVE-2019-3598
McAfee Agent (MA) General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via specifically crafted UDP packets.