|
223611
|
5.4 |
MEDIUM
Network
|
digitalalertsystems
|
dasdec_ii_firmware one-net_se_firmware dasdec_i_firmware one-net_firmware dasdec_iii_firmware
|
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH usernam…
|
-
|
CVE-2019-18265
|
2024-11-21 13:32 |
2022-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223612
|
5.3 |
MEDIUM
Network
|
apache fedoraproject oracle
|
http_server fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit
|
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing …
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17567
|
2024-11-21 13:32 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223613
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortios fortiproxy
|
A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated r…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17656
|
2024-11-21 13:32 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223614
|
9.8 |
CRITICAL
Network
|
advantech
|
spectre_rt_ert351_firmware
|
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force pa…
|
-
|
CVE-2019-18235
|
2024-11-21 13:32 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223615
|
6.1 |
MEDIUM
Network
|
advantech
|
spectre_rt_ert351_firmware
|
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.
|
-
|
CVE-2019-18233
|
2024-11-21 13:32 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223616
|
7.5 |
HIGH
Network
|
advantech
|
spectre_rt_ert351_firmware
|
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.
|
-
|
CVE-2019-18231
|
2024-11-21 13:32 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223617
|
5.5 |
MEDIUM
Local
|
ge
|
ifix
|
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18243
|
2024-11-21 13:32 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223618
|
5.5 |
MEDIUM
Local
|
ge
|
ifix
|
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18255
|
2024-11-21 13:32 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223619
|
9.8 |
CRITICAL
Network
|
libzip
|
libzip
|
A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer s…
|
CWE-416
Use After Free
|
CVE-2019-17582
|
2024-11-21 13:32 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223620
|
7.5 |
HIGH
Network
|
apache oracle
|
batik api_gateway hyperion_financial_reporting enterprise_repository business_intelligence retail_order_broker hospitality_opera_5 communications_application_session_controller
|
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vu…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17566
|
2024-11-21 13:32 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|