6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-20434
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2019 2 PoCs

An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Datasource creation page of the Management Console.

CVE-2019-11255
kubernetes-csi external-provisioner DevOps
4.8
MEDIUM
EPSS
0.9%
2019 CWE-20 1 PoC

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

CVE-2019-25368
OPNsense Web Cloud
4.8
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption, and Nextcloud_backupdir. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.

CVE-2019-25367
ArangoDB Community Edition Web
4.8
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.

CVE-2019-3602
McAfee Network Security Manager (NSM) Web
4.8
MEDIUM
EPSS
0.2%
2019 1 PoC

Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.

CVE-2019-11035
PHP Web
4.8
MEDIUM
EPSS
3.0%
2019 CWE-125 2 PoCs

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.

CVE-2019-11050
PHP Web
4.8
MEDIUM
EPSS
3.2%
2019 CWE-125 1 PoC

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

CVE-2019-20752
Software Genérico Web
4.8
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7800 before 1.0.2.58, R8900 before 1.0.4.12, R9000 before 1.0.4.12, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, WN3000RPv2 before 1.0.0.68, WN3000RPv3 before 1.0.2.70, WN3100RPv2 before 1.0.0.60, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.68.

CVE-2019-1881
Cisco Industrial Network Director Web Networking
4.7
MEDIUM
EPSS
0.3%
2019 CWE-352 1 PoC

A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to use a web browser and the privileges of the user to perform arbitra

CVE-2019-10207
kernel General
4.7
MEDIUM
EPSS
0.7%
2019 CWE-476 1 PoC

A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.

CVE-2019-3882
kernel General
4.7
MEDIUM
EPSS
0.0%
2019 CWE-770 2 PoCs

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.

CVE-2019-8995
TIBCO ActiveMatrix BPM General
4.7
MEDIUM
EPSS
0.2%
2019 1 PoC

The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a vulnerability wherein a malicious URL could trick a user into visiting a website of the attacker's choice. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up to and including 4.2.0, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM

CVE-2019-25353
Foscam Video Management System General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

Foscam Video Management System 1.1.4.9 contains a denial of service vulnerability in the username input field that allows attackers to crash the application. Attackers can overwrite the username with a 520-byte buffer of repeated 'A' characters to trigger an application crash during device login.

CVE-2019-20480
Software Genérico Web
4.6
MEDIUM
EPSS
0.3%
2019 1 PoC

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.

CVE-2019-20648
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2019 1 PoC

NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.

CVE-2019-20481
Software Genérico General
4.6
MEDIUM
EPSS
0.3%
2019 1 PoC

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

CVE-2019-25349
scadaApp for iOS General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices.

CVE-2019-3653
McAfee Endpoint Security (ENS) General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-284 1 PoC

Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.

CVE-2019-25326
ipPulse General
4.6
MEDIUM
EPSS
0.0%
2019 CWE-120 1 PoC

ipPulse 1.92 contains a denial of service vulnerability that allows local attackers to crash the application by providing an oversized input in the Enter Key field. Attackers can generate a 256-byte buffer of repeated 'A' characters to trigger an application crash when pasting the malicious content.

CVE-2019-4723
Cognos Analytics General
4.6
MEDIUM
EPSS
0.5%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.