|
223291
|
9.8 |
CRITICAL
Network
|
crestron
|
dmc-stro_firmware
|
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
|
CWE-78
OS Command
|
CVE-2019-18184
|
2024-11-21 13:32 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223292
|
8.8 |
HIGH
Network
|
csrf_magic_project
|
csrf_magic
|
The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit th…
|
CWE-352
Origin Validation Error
|
CVE-2019-17590
|
2024-11-21 13:32 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223293
|
9.8 |
CRITICAL
Network
|
progress
|
sitefinity
|
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-17392
|
2024-11-21 13:32 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223294
|
8.8 |
HIGH
Network
|
-
|
-
|
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requ…
|
NVD-CWE-noinfo
|
CVE-2019-18251
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223295
|
9.8 |
CRITICAL
Network
|
abb
|
plant_connect power_generation_information_manager
|
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authe…
|
CWE-287
Improper Authentication
|
CVE-2019-18250
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223296
|
6.5 |
MEDIUM
Adjacent
|
philips
|
intellibridge_ec40_firmware intellibridge_ec80_firmware
|
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphe…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-18241
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223297
|
6.1 |
MEDIUM
Network
|
eclipse
|
jetty
|
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escap…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17632
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223298
|
5.3 |
MEDIUM
Network
|
nokia
|
impact
|
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
|
CWE-22
Path Traversal
|
CVE-2019-17406
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223299
|
6.1 |
MEDIUM
Network
|
nokia
|
impact
|
Nokia IMPACT < 18A: has Reflected self XSS
|
CWE-79
Cross-site Scripting
|
CVE-2019-17405
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223300
|
4.3 |
MEDIUM
Network
|
nokia
|
impact
|
Nokia IMPACT < 18A: allows full path disclosure
|
CWE-22
Path Traversal
|
CVE-2019-17404
|
2024-11-21 13:32 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|