|
222921
|
5.9 |
MEDIUM
Network
|
mitsubishielectric
|
q03\/04\/06\/13\/26udvcpu_firmware q04\/06\/13\/26udpvcpu_firmware q03udecpu_firmware q04\/06\/10\/13\/20\/26\/50\/100udehcpu_firmware l02\/06\/26cpu_firmware l26cpu-bt_firmware l02…
|
In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial number 21081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: seria…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-13555
|
2024-11-21 13:25 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222922
|
7.5 |
HIGH
Network
|
medtronic
|
valleylab_exchange_client valleylab_ft10_energy_platform_firmware valleylab_fx8_energy_platform_firmware
|
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13543
|
2024-11-21 13:25 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222923
|
4.6 |
MEDIUM
Physics
|
medtronic
|
valleylab_ft10_energy_platform_firmware valleylab_ls10_energy_platform_firmware
|
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-13535
|
2024-11-21 13:25 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222924
|
7.8 |
HIGH
Local
|
medtronic
|
valleylab_exchange_client valleylab_ft10_energy_platform_firmware valleylab_fx8_energy_platform_firmware
|
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-13539
|
2024-11-21 13:25 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222925
|
4.6 |
MEDIUM
Physics
|
medtronic
|
valleylab_ft10_energy_platform_firmware valleylab_ls10_energy_platform_firmware
|
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version …
|
NVD-CWE-noinfo
|
CVE-2019-13531
|
2024-11-21 13:25 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222926
|
5.3 |
MEDIUM
Network
|
philips
|
tasy_emr tasy_webportal
|
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.
|
CWE-200
Information Exposure
|
CVE-2019-13557
|
2024-11-21 13:25 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222927
|
6.5 |
MEDIUM
Network
|
oneidentity
|
cloud_access_manager
|
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
|
CWE-352
Origin Validation Error
|
CVE-2019-13497
|
2024-11-21 13:25 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222928
|
8.1 |
HIGH
Network
|
oneidentity
|
cloud_access_manager
|
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a suc…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2019-13496
|
2024-11-21 13:25 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222929
|
9.8 |
CRITICAL
Network
|
advantech
|
wise-paas\/rmm
|
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can l…
|
CWE-22
Path Traversal
|
CVE-2019-13551
|
2024-11-21 13:25 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222930
|
9.8 |
CRITICAL
Network
|
advantech
|
wise-paas\/rmm
|
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13547
|
2024-11-21 13:25 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|