|
223181
|
7.5 |
HIGH
Network
|
br-automation
|
industrial_automation_aprol
|
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than …
|
NVD-CWE-noinfo
|
CVE-2019-19873
|
2024-11-21 13:35 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223182
|
9.8 |
CRITICAL
Network
|
br-automation
|
industrial_automation_aprol
|
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a d…
|
CWE-77
Command Injection
|
CVE-2019-19872
|
2024-11-21 13:35 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223183
|
7.5 |
HIGH
Network
|
br-automation
|
industrial_automation_aprol
|
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.
|
NVD-CWE-noinfo
|
CVE-2019-19869
|
2024-11-21 13:35 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223184
|
9.1 |
CRITICAL
Network
|
bender
|
com465ip_firmware com465dp_firmware com465id_firmware cp700_firmware cp907_firmware cp915_firmware
|
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorizati…
|
CWE-862
Missing Authorization
|
CVE-2019-19885
|
2024-11-21 13:35 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223185
|
7.5 |
HIGH
Network
|
ise
|
smart_connect_knx_vaillant
|
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-19643
|
2024-11-21 13:35 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223186
|
7.5 |
HIGH
Network
|
jetbrains
|
upsource
|
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
|
NVD-CWE-noinfo
|
CVE-2019-19704
|
2024-11-21 13:35 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223187
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19935
|
2024-11-21 13:35 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223188
|
7.8 |
HIGH
Local
|
videolan
|
vlc_media_player
|
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted i…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-19721
|
2024-11-21 13:35 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223189
|
7.2 |
HIGH
Network
|
centreon
|
centreon
|
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguratio…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19699
|
2024-11-21 13:35 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223190
|
4.8 |
MEDIUM
Network
|
intland
|
codebeamer
|
In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19913
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|