|
212521
|
9.8 |
CRITICAL
Network
|
nice
|
engage
|
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers t…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7727
|
2024-11-21 13:48 |
2019-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212522
|
9.8 |
CRITICAL
Network
|
auth0
|
auth0-wcf-service-jwt
|
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-7644
|
2024-11-21 13:48 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212523
|
9.0 |
CRITICAL
Network
|
cantemo
|
portal
|
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could en…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7551
|
2024-11-21 13:48 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212524
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_p\&id autocad_plant_3d civil_3d
|
An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Aut…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-7361
|
2024-11-21 13:48 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212525
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_p\&id autocad_plant_3d civil_3d
|
An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 201…
|
CWE-416
Use After Free
|
CVE-2019-7360
|
2024-11-21 13:48 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212526
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_p\&id autocad_plant_3d civil_3d
|
An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 201…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-7359
|
2024-11-21 13:48 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212527
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_p\&id autocad_plant_3d civil_3d
|
An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-7358
|
2024-11-21 13:48 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212528
|
7.5 |
HIGH
Network
|
sonicwall
|
sonicos sonicosv
|
A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are enabled. This vulnerability affected SonicOS Gen …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-7477
|
2024-11-21 13:48 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212529
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sonicos sonicosv
|
A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced routing services. This vulnerability affected Son…
|
NVD-CWE-Other
|
CVE-2019-7475
|
2024-11-21 13:48 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212530
|
6.5 |
MEDIUM
Network
|
sonicwall
|
sonicos sonicosv
|
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading certificate with specific extension. This vulnerabilit…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-7474
|
2024-11-21 13:48 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|