|
222471
|
7.8 |
HIGH
Local
|
broadcom
|
brocade_sannav
|
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16207
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222472
|
5.5 |
MEDIUM
Local
|
broadcom
|
brocade_sannav
|
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker…
|
CWE-532 CWE-311
Inclusion of Sensitive Information in Log Files Missing Encryption of Sensitive Data
|
CVE-2019-16206
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222473
|
8.8 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several po…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-16205
|
2024-11-21 13:30 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222474
|
6.5 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s8_plus_firmware galaxy_s3_firmware galaxy_note_2_firmware
|
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build N…
|
NVD-CWE-noinfo
|
CVE-2019-16401
|
2024-11-21 13:30 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222475
|
6.5 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s8_plus_firmware galaxy_s3_firmware galaxy_note_2_firmware
|
Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build N…
|
NVD-CWE-noinfo
|
CVE-2019-16400
|
2024-11-21 13:30 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222476
|
7.2 |
HIGH
Network
|
hp
|
260_g1_dm_firmware 280_pro_g1_firmware 285_g2_firmware 340_g3_firmware 340_g4_firmware 346_g3_firmware 346_g4_firmware 348_g3_firmware 348_g4_firmware elite_slice_firmware<…
|
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of pr…
|
NVD-CWE-noinfo
|
CVE-2019-16284
|
2024-11-21 13:30 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222477
|
7.8 |
HIGH
Local
|
phoenixcontact
|
pc_worx_express config\+ pc_worx
|
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds R…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16675
|
2024-11-21 13:30 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222478
|
4.6 |
MEDIUM
Local
|
control-webpanel
|
webpanel
|
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename …
|
CWE-79
Cross-site Scripting
|
CVE-2019-16295
|
2024-11-21 13:30 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222479
|
4.3 |
MEDIUM
Network
|
yithemes
|
yith_woocommerce_wishlist yith_woocommerce_compare yith_woocommerce_quick_view yith_woocommerce_zoom_magnifier yith_woocommerce_ajax_search yith_woocommerce_badge_management yith_wo…
|
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
|
NVD-CWE-noinfo
|
CVE-2019-16251
|
2024-11-21 13:30 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222480
|
7.2 |
HIGH
Network
|
maxthon
|
maxthon_browser
|
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-16647
|
2024-11-21 13:30 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|