|
222981
|
7.5 |
HIGH
Network
|
citrix
|
storefront_server
|
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
|
CWE-611
XXE
|
CVE-2019-13608
|
2024-11-21 13:25 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222982
|
5.3 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13599
|
2024-11-21 13:25 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222983
|
7.8 |
HIGH
Local
|
fujielectric
|
alpha5_smart_loader_firmware
|
Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted project files to overflow the buffer and execute code u…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13520
|
2024-11-21 13:25 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222984
|
8.8 |
HIGH
Network
|
osisoft
|
pi_web_api
|
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.
|
CWE-352
Origin Validation Error
|
CVE-2019-13516
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222985
|
6.5 |
MEDIUM
Network
|
osisoft
|
pi_web_api
|
OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-13515
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222986
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_dopsoft
|
In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger a use-after-free vulnerability, which may allow information disclosure, r…
|
CWE-416
Use After Free
|
CVE-2019-13514
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222987
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_dopsoft
|
In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger multiple out-of-bounds read vulnerabilities, which may allow information …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13513
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222988
|
3.3 |
LOW
Local
|
fujielectric
|
frenic_loader
|
Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an attacker to read limited information from the device.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13512
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222989
|
3.3 |
LOW
Local
|
rockwellautomation
|
arena_simulation_software
|
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the …
|
CWE-416
Use After Free
|
CVE-2019-13511
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222990
|
7.8 |
HIGH
Local
|
rockwellautomation
|
arena_simulation_software
|
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the applica…
|
CWE-416
Use After Free
|
CVE-2019-13510
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|