|
212681
|
8.1 |
HIGH
Network
|
jio
|
jmr1140_firmware
|
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value ca…
|
CWE-352
Origin Validation Error
|
CVE-2019-7746
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212682
|
9.8 |
CRITICAL
Network
|
jio
|
jmr1140_firmware
|
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the wpa_security_key f…
|
NVD-CWE-noinfo
|
CVE-2019-7745
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212683
|
6.1 |
MEDIUM
Network
|
jio
|
jmr1140_firmware
|
cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7687
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212684
|
9.8 |
CRITICAL
Network
|
coship
|
rt3052_firmware rt3050_firmware wm3300_firmware rt7620_firmware
|
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST requ…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7564
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212685
|
6.1 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7541
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212686
|
8.1 |
HIGH
Network
|
kde opensuse fedoraproject
|
kauth leap backports fedora
|
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of …
|
CWE-20
Improper Input Validation
|
CVE-2019-7443
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212687
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7427
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212688
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7426
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212689
|
8.1 |
HIGH
Network
|
sonicwall
|
global_management_system
|
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-7476
|
2024-11-21 13:48 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212690
|
9.8 |
CRITICAL
Network
|
nice
|
engage
|
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers t…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7727
|
2024-11-21 13:48 |
2019-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|