|
219881
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3987
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219882
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3986
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219883
|
8.8 |
HIGH
Adjacent
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration v…
|
CWE-78
OS Command
|
CVE-2019-3985
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219884
|
6.8 |
MEDIUM
Physics
|
amazon
|
blink_xt2_sync_module_firmware
|
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-3983
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219885
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4665
|
2024-11-21 13:43 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219886
|
5.4 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…
|
CWE-79
Cross-site Scripting
|
CVE-2019-4663
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219887
|
9.8 |
CRITICAL
Network
|
ibm
|
cloud_pak_system
|
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-4521
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219888
|
9.1 |
CRITICAL
Network
|
ibm
|
smartcloud_analytics_log_analysis
|
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-4244
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219889
|
4.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_system
|
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X…
|
CWE-352
Origin Validation Error
|
CVE-2019-4095
|
2024-11-21 13:43 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219890
|
9.8 |
CRITICAL
Network
|
ibm
|
datapower_gateway
|
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use th…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-4621
|
2024-11-21 13:43 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|