|
210991
|
7.8 |
HIGH
Local
|
alarm
|
adc-v522ir_firmware
|
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN se…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-9657
|
2024-11-21 13:52 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210992
|
7.5 |
HIGH
Network
|
sonatype
|
nexus_repository_manager
|
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-9630
|
2024-11-21 13:52 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210993
|
9.8 |
CRITICAL
Network
|
sonatype
|
nexus_repository_manager
|
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
|
CWE-287
Improper Authentication
|
CVE-2019-9629
|
2024-11-21 13:52 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210994
|
9.8 |
CRITICAL
Network
|
hawt
|
hawtio
|
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-9827
|
2024-11-21 13:52 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210995
|
9.8 |
CRITICAL
Network
|
jetbrains
|
intellij_idea
|
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. …
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-9873
|
2024-11-21 13:52 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210996
|
9.8 |
CRITICAL
Network
|
jetbrains
|
intellij_idea
|
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration fil…
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-9823
|
2024-11-21 13:52 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210997
|
8.1 |
HIGH
Network
|
jetbrains
|
intellij_idea
|
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE …
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-9872
|
2024-11-21 13:52 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210998
|
7.8 |
HIGH
Local
|
symantec
|
endpoint_encryption
|
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that ar…
|
NVD-CWE-noinfo
|
CVE-2019-9703
|
2024-11-21 13:52 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210999
|
7.8 |
HIGH
Local
|
symantec
|
endpoint_encryption
|
Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that ar…
|
NVD-CWE-noinfo
|
CVE-2019-9702
|
2024-11-21 13:52 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211000
|
7.5 |
HIGH
Network
|
diffplug
|
gradle maven
|
In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolve…
|
CWE-611
XXE
|
CVE-2019-9843
|
2024-11-21 13:52 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|