|
219221
|
9.8 |
CRITICAL
Network
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration da…
|
CWE-78
OS Command
|
CVE-2019-3989
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219222
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3988
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219223
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3987
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219224
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3986
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219225
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3985
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219226
|
6.8 |
MEDIUM
Physics
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3983
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219227
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4665
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219228
|
5.4 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4663
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219229
|
9.8 |
CRITICAL
Network
|
ibm
|
cloud_pak_system
|
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-4521
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219230
|
9.1 |
CRITICAL
Network
|
ibm
|
smartcloud_analytics_log_analysis
|
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-4244
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|