|
223931
|
8.8 |
HIGH
Network
|
comelitgroup
|
away_from_home
|
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an at…
|
CWE-269
Improper Privilege Management
|
CVE-2019-14453
|
2024-11-21 13:26 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223932
|
7.8 |
HIGH
Local
|
tianocore
|
edk2
|
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14584
|
2024-11-21 13:26 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223933
|
5.4 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to …
|
CWE-352
Origin Validation Error
|
CVE-2019-14481
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223934
|
8.8 |
HIGH
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.
|
CWE-78
OS Command
|
CVE-2019-14479
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223935
|
5.4 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This d…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14478
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223936
|
6.5 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-14476
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223937
|
8.8 |
HIGH
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential man…
|
NVD-CWE-noinfo
|
CVE-2019-14483
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223938
|
9.8 |
CRITICAL
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no oth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-14482
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223939
|
9.8 |
CRITICAL
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
|
CWE-200 CWE-338 CWE-311 CWE-522 CWE-732
Information Exposure Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Missing Encryption of Sensitive Data Insufficiently Protected Credentials Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14480
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223940
|
5.5 |
MEDIUM
Local
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-14477
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|