|
212851
|
9.1 |
CRITICAL
Network
|
johnsoncontrols
|
metasys_system
|
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-7594
|
2024-11-21 13:48 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212852
|
9.1 |
CRITICAL
Network
|
johnsoncontrols
|
metasys_system
|
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-7593
|
2024-11-21 13:48 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212853
|
7.8 |
HIGH
Local
|
adobe
|
premiere_pro_cc
|
Adobe Premiere Pro CC versions 13.1.2 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-7931
|
2024-11-21 13:48 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212854
|
7.8 |
HIGH
Local
|
adobe
|
character_animator
|
Adobe Character Animator versions 2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-7870
|
2024-11-21 13:48 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212855
|
7.5 |
HIGH
Network
|
magento
|
magento
|
An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A SOAP web service endpoint does not properly enforce parameters re…
|
NVD-CWE-noinfo
|
CVE-2019-7951
|
2024-11-21 13:48 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212856
|
7.5 |
HIGH
Network
|
magento
|
magento
|
An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthenticated user can bypass access controls via REST API c…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-7950
|
2024-11-21 13:48 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212857
|
6.5 |
MEDIUM
Network
|
magento
|
magento
|
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18,…
|
CWE-352
Origin Validation Error
|
CVE-2019-7947
|
2024-11-21 13:48 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212858
|
5.4 |
MEDIUM
Network
|
magento
|
magento
|
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7945
|
2024-11-21 13:48 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212859
|
5.4 |
MEDIUM
Network
|
magento
|
magento
|
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento …
|
CWE-79
Cross-site Scripting
|
CVE-2019-7944
|
2024-11-21 13:48 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212860
|
7.2 |
HIGH
Network
|
magento
|
magento
|
A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to create or edit a pr…
|
NVD-CWE-noinfo
|
CVE-2019-7942
|
2024-11-21 13:48 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|