|
221731
|
7.8 |
HIGH
Local
|
tobesoft
|
xplatform
|
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.
|
CWE-416
Use After Free
|
CVE-2019-19162
|
2024-11-21 13:34 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221732
|
8.8 |
HIGH
Network
|
raonwiz
|
dext5
|
dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by setting the arguments to the activex method. A remote…
|
NVD-CWE-noinfo
|
CVE-2019-19164
|
2024-11-21 13:34 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221733
|
9.8 |
CRITICAL
Network
|
raonwiz
|
dext5
|
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leve…
|
NVD-CWE-noinfo
|
CVE-2019-19169
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221734
|
9.8 |
CRITICAL
Network
|
raonwiz
|
dext5
|
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex metho…
|
NVD-CWE-noinfo
|
CVE-2019-19168
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221735
|
9.8 |
CRITICAL
Network
|
tobesoft
|
nexacro
|
Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execut…
|
NVD-CWE-noinfo
|
CVE-2019-19167
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221736
|
7.8 |
HIGH
Local
|
tobesoft
|
xplatform
|
Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.
|
NVD-CWE-noinfo
|
CVE-2019-19166
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221737
|
8.8 |
HIGH
Network
|
intelbras
|
action_rf_1200_firmware
|
Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
|
CWE-352
Origin Validation Error
|
CVE-2019-19517
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221738
|
6.1 |
MEDIUM
Network
|
ayision
|
ays-wr01_firmware
|
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19515
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221739
|
5.4 |
MEDIUM
Network
|
ayision
|
ays-wr01_firmware
|
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19514
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221740
|
8.8 |
HIGH
Network
|
bmcsoftware
|
control-m\/agent
|
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
|
CWE-78
OS Command
|
CVE-2019-19220
|
2024-11-21 13:34 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|