6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25682
CMSsite Web
5.3
MEDIUM
EPSS
0.0%
2019 CWE-352 1 PoC

CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts.

CVE-2019-25230
Xperience General
5.3
MEDIUM
EPSS
0.1%
2019 CWE-497 1 PoC

An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.

CVE-2019-3883
389-ds-base Windows
5.3
MEDIUM
EPSS
0.9%
2019 CWE-772 1 PoC

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVE-2019-4471
Cognos Analytics Web
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.

CVE-2019-20101
Jira Server General
5.3
MEDIUM
EPSS
1.6%
2019 1 PoC

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVE-2019-3650
Advanced Threat Defense (ATD) General
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET request extracting insecurely information stored in the database.

CVE-2019-15165
Software Genérico General
5.3
MEDIUM
EPSS
1.0%
2019 1 PoC

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

CVE-2019-25379
Smoothwall Express Web
5.3
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST requests with script payloads in the REDIRECT_PAGE or CHILDREN parameters to execute arbitrary JavaScript in user browsers.

CVE-2019-20694
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects GS728TP before 6.0.0.48, GS728TPPv2 before 6.0.0.48, GS728TPv2 before 6.0.0.48, GS752TPP before 6.0.0.48, and GS752TPv2 before 6.0.0.48.

CVE-2019-5043
Nest Labs General
5.3
MEDIUM
EPSS
0.2%
2019 CWE-400 1 PoC

An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multiple times to trigger this vulnerability.

CVE-2019-19003
eSOMS Web
5.3
MEDIUM
EPSS
0.4%
2019 CWE-16 1 PoC

For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.

CVE-2019-17335
TIBCO Spotfire Analytics Platform for AWS Marketplace Cloud
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an attacker access to data cached from a data source, or a portion of a data source, that the attacker should not have access to. The attacker would need privileges to save a Spotfire file to the library. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0 and TIBCO Spotfire Server: versions 7.11.7 and below, versions 7.12.0, 7.13.0, 7.14.0

CVE-2019-11048
PHP Web
5.3
MEDIUM
EPSS
12.7%
2019 CWE-400 6 PoCs

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

CVE-2019-25062
IP CCTV Camera General
5.3
MEDIUM
EPSS
0.1%
2019 CWE-121 2 PoCs

A vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processing of the component Device Viewer. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVE-2019-25395
Smoothwall Express Web
5.3
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the preferences page.

CVE-2019-17655
Fortinet FortiOS and FortiProxy Networking
5.3
MEDIUM
EPSS
0.2%
2019 1 PoC

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

CVE-2019-1622
Cisco Data Center Network Manager Networking
5.3
MEDIUM
EPSS
84.8%
2019 CWE-284 5 PoCs

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit could allow the attacker to download log files and diagnostic information from the affected device.

CVE-2019-9510
Windows 10 or newer system using RDP Windows
5.3
MEDIUM
EPSS
1.0%
2019 CWE-288 1 PoC

A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP disconnect, Automatic Reconnection of the RDP session will be restored to an unlocked state, regardless of how the remote system was left. By interrupting network connectivity of a system, an attacker with access to a system being used as a Windows RDP client can gain access to a connected remote system, regardless of whether

CVE-2019-3643
McAfee Web Gateway (MWG) General
5.3
MEDIUM
EPSS
0.5%
2019 1 PoC

McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.

CVE-2019-3888
undertow Web Windows
5.3
MEDIUM
EPSS
0.6%
2019 CWE-532 1 PoC

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)