|
222321
|
5.3 |
MEDIUM
Network
|
virginmedia
|
super_hub_3_firmware
|
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebi…
|
CWE-863
Incorrect Authorization
|
CVE-2019-16651
|
2024-11-21 13:30 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222322
|
4.8 |
MEDIUM
Network
|
zohocorp
|
manageengine_remote_access_plus
|
Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16268
|
2024-11-21 13:30 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222323
|
7.5 |
HIGH
Network
|
ptarmigan_project
|
ptarmigan
|
Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code block.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16281
|
2024-11-21 13:30 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222324
|
6.8 |
MEDIUM
Physics
|
microchip
|
cryptoauthlib
|
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-16128
|
2024-11-21 13:30 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222325
|
6.8 |
MEDIUM
Physics
|
microchip
|
cryptoauthlib
|
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-16129
|
2024-11-21 13:30 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222326
|
9.1 |
CRITICAL
Network
|
microchip
|
advanced_software_framework_4
|
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-16127
|
2024-11-21 13:30 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222327
|
7.5 |
HIGH
Network
|
mikrotik
|
routeros
|
An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2019-16160
|
2024-11-21 13:30 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222328
|
8.8 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authen…
|
NVD-CWE-Other
|
CVE-2019-16212
|
2024-11-21 13:30 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222329
|
9.8 |
CRITICAL
Network
|
broadcom
|
brocade_sannav
|
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16211
|
2024-11-21 13:30 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222330
|
9.8 |
CRITICAL
Network
|
pega
|
platform
|
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * charact…
|
NVD-CWE-Other
|
CVE-2019-16374
|
2024-11-21 13:30 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|