|
219561
|
8.8 |
HIGH
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially craf…
|
NVD-CWE-noinfo
|
CVE-2019-20029
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219562
|
7.5 |
HIGH
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice resp…
|
NVD-CWE-noinfo
|
CVE-2019-20028
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219563
|
9.8 |
CRITICAL
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password…
|
CWE-287
Improper Authentication
|
CVE-2019-20027
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219564
|
7.5 |
HIGH
Network
|
nec
|
sv9100_firmware
|
The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.
|
NVD-CWE-noinfo
|
CVE-2019-20026
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219565
|
9.8 |
CRITICAL
Network
|
nec
|
sv9100_firmware
|
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-20025
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219566
|
7.8 |
HIGH
Local
|
solarwinds
|
webhelpdesk
|
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a Tic…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-20002
|
2024-11-21 13:37 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219567
|
3.7 |
LOW
Network
|
cisco
|
webex_business_suite_39
|
Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-1866
|
2024-11-21 13:37 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219568
|
7.8 |
HIGH
Local
|
zsh fedoraproject debian apple
|
zsh fedora debian_linux mac_os_x iphone_os watchos tvos ipados
|
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by …
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2019-20044
|
2024-11-21 13:37 |
2020-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219569
|
8.4 |
HIGH
Local
|
cisco
|
ios_xe
|
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default …
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-1950
|
2024-11-21 13:37 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219570
|
9.8 |
CRITICAL
Network
|
s3india
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may al…
|
CWE-287
Improper Authentication
|
CVE-2019-20046
|
2024-11-21 13:37 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|