6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-9581
Software Genérico Web
N/A
UNKNOWN
EPSS
17.0%
2019 3 PoCs

phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.

CVE-2019-20075
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).

CVE-2019-6790
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests.

CVE-2019-16067
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.

CVE-2019-2473
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depen

CVE-2019-15728
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVE-2019-9891
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.

CVE-2019-2852
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a p

CVE-2019-19076
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2019 1 PoC

A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted

CVE-2019-11591
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 3 PoCs

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVE-2019-15401
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ASUS_A002 Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-instal

CVE-2019-16261
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.

CVE-2019-7610
Kibana Web
N/A
UNKNOWN
EPSS
1.1%
2019 CWE-94 2 PoCs

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVE-2019-13066
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.

CVE-2019-11629
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.

CVE-2019-19199
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 3 PoCs

REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.

CVE-2019-0129
Intel(R) USB 3.0 Creator Utility General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-20551
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via a Class 0 Type Message. The Samsung ID is SVE-2019-14941 (October 2019).

CVE-2019-14836
Red Hat 3scale API Management Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

CVE-2019-17603
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.