|
223701
|
9.8 |
CRITICAL
Network
|
hinet
|
gpon_firmware
|
HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15064
|
2024-11-21 13:27 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223702
|
7.5 |
HIGH
Network
|
redhat
|
keycloak
|
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could …
|
CWE-863
Incorrect Authorization
|
CVE-2019-14832
|
2024-11-21 13:27 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223703
|
7.8 |
HIGH
Local
|
ubisoft
|
uplay
|
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14737
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223704
|
4.9 |
MEDIUM
Network
|
redhat
|
wildfly_core jboss_enterprise_application_platform single_sign-on data_grid
|
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
|
CWE-269
Improper Privilege Management
|
CVE-2019-14838
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223705
|
7.4 |
HIGH
Network
|
jss_cryptomanager_project redhat
|
jss_cryptomanager enterprise_linux enterprise_linux_desktop enterprise_linux_eus enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_…
|
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. …
|
-
|
CVE-2019-14823
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223706
|
5.5 |
MEDIUM
Local
|
redhat
|
ansible_engine ansible_tower
|
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name t…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-14858
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223707
|
8.8 |
HIGH
Network
|
softing
|
uagate_si_firmware uagate_mb_firmware uagate_840d_firmware
|
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.
|
CWE-77
Command Injection
|
CVE-2019-15051
|
2024-11-21 13:27 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223708
|
5.9 |
MEDIUM
Network
|
arista
|
extensible_operating_system
|
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer …
|
CWE-362
Race Condition
|
CVE-2019-14810
|
2024-11-21 13:27 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223709
|
7.5 |
HIGH
Network
|
zingbox
|
inspector
|
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configuration.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-15023
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223710
|
7.5 |
HIGH
Network
|
zingbox
|
inspector
|
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-15022
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|