|
223421
|
9.8 |
CRITICAL
Network
|
weidmueller
|
ie-sw-pl09m-5gc-4gt_firmware ie-sw-pl09mt-5gc-4gt_firmware ie-sw-pl18m-2gc-16tx_firmware ie-sw-pl18mt-2gc-16tx_firmware ie-sw-pl18m-2gc14tx2sc_firmware ie-sw-pl18mt-2gc14tx2sc_firmware…
|
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-16672
|
2024-11-21 13:30 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223422
|
6.5 |
MEDIUM
Network
|
weidmueller
|
ie-sw-pl09m-5gc-4gt_firmware ie-sw-pl09mt-5gc-4gt_firmware ie-sw-pl18m-2gc-16tx_firmware ie-sw-pl18mt-2gc-16tx_firmware ie-sw-pl18m-2gc14tx2sc_firmware ie-sw-pl18mt-2gc14tx2sc_firmware…
|
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a devic…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-16671
|
2024-11-21 13:30 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223423
|
9.8 |
CRITICAL
Network
|
weidmueller
|
ie-sw-pl09m-5gc-4gt_firmware ie-sw-pl09mt-5gc-4gt_firmware ie-sw-pl18m-2gc-16tx_firmware ie-sw-pl18mt-2gc-16tx_firmware ie-sw-pl18m-2gc14tx2sc_firmware ie-sw-pl18mt-2gc14tx2sc_firmware…
|
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-fo…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-16670
|
2024-11-21 13:30 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223424
|
4.3 |
MEDIUM
Network
|
pega
|
pega_platform
|
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. N…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-16388
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223425
|
4.3 |
MEDIUM
Network
|
pega
|
pega_platform
|
PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get databas…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-16386
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223426
|
8.1 |
HIGH
Network
|
pega
|
pega_platform
|
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform acti…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-16387
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223427
|
8.1 |
HIGH
Network
|
ruby-lang debian opensuse oracle
|
ruby debian_linux leap graalvm
|
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. …
|
CWE-94
Code Injection
|
CVE-2019-16255
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223428
|
5.3 |
MEDIUM
Network
|
ruby-lang debian
|
ruby debian_linux
|
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit i…
|
CWE-74
Injection
|
CVE-2019-16254
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223429
|
7.5 |
HIGH
Network
|
ruby-lang debian
|
ruby debian_linux
|
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBr…
|
CWE-287
Improper Authentication
|
CVE-2019-16201
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223430
|
6.1 |
MEDIUM
Network
|
centreon
|
centreon
|
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16195
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|