|
222371
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortisiem
|
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16153
|
2024-11-21 13:30 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222372
|
7.5 |
HIGH
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2019-16469
|
2024-11-21 13:30 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222373
|
7.5 |
HIGH
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
|
CWE-74
Injection
|
CVE-2019-16468
|
2024-11-21 13:30 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222374
|
6.1 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16467
|
2024-11-21 13:30 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222375
|
6.1 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16466
|
2024-11-21 13:30 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222376
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortiauthenticator
|
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16154
|
2024-11-21 13:30 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222377
|
5.3 |
MEDIUM
Network
|
dten
|
d5_firmware d7_firmware
|
DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16271
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222378
|
7.5 |
HIGH
Network
|
dten
|
d5_firmware d7_firmware
|
DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-16274
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222379
|
9.8 |
CRITICAL
Network
|
dten
|
d5_firmware d7_firmware
|
DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a co…
|
NVD-CWE-noinfo
|
CVE-2019-16273
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222380
|
9.8 |
CRITICAL
Network
|
dten
|
d5_firmware d7_firmware
|
On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-16272
|
2024-11-21 13:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|