|
210901
|
6.8 |
MEDIUM
Physics
|
symantec
|
norton_core_firmware
|
Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that has the potential of allowing an individual to execute arbitrary commands or c…
|
NVD-CWE-noinfo
|
CVE-2019-9695
|
2024-11-21 13:52 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210902
|
6.5 |
MEDIUM
Network
|
amazon_affiliate_store_project
|
amazon_affiliate_store
|
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount.
|
NVD-CWE-noinfo
|
CVE-2019-9864
|
2024-11-21 13:52 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210903
|
9.8 |
CRITICAL
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware secvest_wireless_remote_control_fube50014_firmware secvest_wireless_remote_control_fube50015_firmware
|
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict v…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-9863
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210904
|
6.5 |
MEDIUM
Adjacent
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware secvest_wireless_remote_control_fube50014_firmware secvest_wireless_remote_control_fube50015_firmware
|
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, …
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-9862
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210905
|
7.5 |
HIGH
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware secvest_wireless_remote_control_fube50014_firmware secvest_wireless_remote_control_fube50015_firmware
|
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlle…
|
CWE-330 CWE-319
Use of Insufficiently Random Values Cleartext Transmission of Sensitive Information
|
CVE-2019-9860
|
2024-11-21 13:52 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210906
|
6.5 |
MEDIUM
Network
|
znc canonical fedoraproject
|
znc ubuntu_linux fedora
|
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
|
CWE-20
Improper Input Validation
|
CVE-2019-9917
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210907
|
8.8 |
HIGH
Network
|
phoenixcontact
|
fl_nat_smn_8tx-m-dmg_firmware fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_nat_smcs_8tx_firmware
|
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from t…
|
CWE-384
Session Fixation
|
CVE-2019-9744
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210908
|
8.8 |
HIGH
Network
|
phoenixcontact
|
rad-80211-xd\/hp-bus_firmware rad-80211-xd_firmware
|
An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.
|
CWE-77
Command Injection
|
CVE-2019-9743
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210909
|
6.1 |
MEDIUM
Network
|
wikindx_project
|
wikindx
|
A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9961
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210910
|
7.4 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is act…
|
CWE-346
Origin Validation Error
|
CVE-2019-9764
|
2024-11-21 13:52 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|