|
220021
|
6.1 |
MEDIUM
Network
|
axiositalia
|
registro_elettronico
|
Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations, the XSS would be on the family.axioscloud.it cloud service; however, the vendo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7693
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220022
|
9.8 |
CRITICAL
Network
|
cim_project
|
cim
|
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call…
|
CWE-94
Code Injection
|
CVE-2019-7692
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220023
|
9.8 |
CRITICAL
Network
|
inxedu
|
inxedu
|
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxe…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-7684
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220024
|
9.8 |
CRITICAL
Network
|
enphase
|
envoy
|
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.
|
CWE-22
Path Traversal
|
CVE-2019-7678
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220025
|
6.1 |
MEDIUM
Network
|
enphase
|
envoy
|
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7677
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220026
|
7.2 |
HIGH
Network
|
enphase
|
envoy
|
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.
|
CWE-521
Weak Password Requirements
|
CVE-2019-7676
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220027
|
7.5 |
HIGH
Network
|
mobotix
|
s14_firmware
|
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html UR…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-7675
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220028
|
9.8 |
CRITICAL
Network
|
mobotix
|
s14_firmware
|
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.
|
CWE-521
Weak Password Requirements
|
CVE-2019-7674
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220029
|
7.5 |
HIGH
Network
|
mobotix
|
s14_firmware
|
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DES hash format.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-7673
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220030
|
5.5 |
MEDIUM
Local
|
elfutils_project debian canonical opensuse redhat
|
elfutils debian_linux ubuntu_linux leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_server_tus enter…
|
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of s…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-7665
|
2024-11-21 13:48 |
2019-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|