|
222651
|
8.8 |
HIGH
Network
|
eyecomms
|
eyecms
|
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-17605
|
2024-11-21 13:32 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222652
|
4.3 |
MEDIUM
Network
|
eyecomms
|
eyecms
|
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV,…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-17604
|
2024-11-21 13:32 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222653
|
7.5 |
HIGH
Network
|
lightbend
|
play_framework
|
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when co…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-17598
|
2024-11-21 13:32 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222654
|
7.5 |
HIGH
Network
|
amazon
|
freertos\+fat
|
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definit…
|
CWE-416
Use After Free
|
CVE-2019-18178
|
2024-11-21 13:32 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222655
|
7.5 |
HIGH
Network
|
honeywell
|
h4d8pr1_firmware hfd5pr1_firmware hpw2p1_firmware hdzp304di_firmware hdzp252di_firmware hdz302din-s1_firmware hdz302lik_firmware hdz302liw_firmware hfd6gr1_firmware hfd8gr1…
|
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-18230
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222656
|
6.5 |
MEDIUM
Network
|
advantech
|
wise-paas\/rmm
|
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose informa…
|
CWE-89
SQL Injection
|
CVE-2019-18229
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222657
|
7.5 |
HIGH
Network
|
advantech
|
wise-paas\/rmm
|
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.
|
CWE-611
XXE
|
CVE-2019-18227
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222658
|
7.5 |
HIGH
Network
|
honeywell
|
h2w2pc1m_firmware h2w2per3_firmware h2w4per3_firmware h4w2per2_firmware h4w2per3_firmware h4w4per2_firmware h4w4per3_firmware h4w8pr2_firmware hbd2per1_firmware hbw2per1_fi…
|
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2019-18228
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222659
|
9.8 |
CRITICAL
Network
|
honeywell
|
h2w2pc1m_firmware h2w2per3_firmware h2w4per3_firmware h4w2per2_firmware h4w2per3_firmware h4w4per2_firmware h4w4per3_firmware h4w8pr2_firmware hbd2per1_firmware hbw2per1_fi…
|
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-18226
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222660
|
6.1 |
MEDIUM
Network
|
apakgroup
|
wholesale_floorplanning_finance
|
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the ma…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17551
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|