|
223761
|
5.3 |
MEDIUM
Network
|
honeywell
|
ip-ak2_firmware
|
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed withou…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13525
|
2024-11-21 13:25 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223762
|
9.8 |
CRITICAL
Network
|
tp-link
|
m7350_firmware
|
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).
|
CWE-78
OS Command
|
CVE-2019-13653
|
2024-11-21 13:25 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223763
|
9.8 |
CRITICAL
Network
|
tp-link
|
m7350_firmware
|
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).
|
CWE-78
OS Command
|
CVE-2019-13652
|
2024-11-21 13:25 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223764
|
9.8 |
CRITICAL
Network
|
tp-link
|
m7350_firmware
|
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).
|
CWE-78
OS Command
|
CVE-2019-13651
|
2024-11-21 13:25 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223765
|
9.8 |
CRITICAL
Network
|
tp-link
|
m7350_firmware
|
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).
|
CWE-78
OS Command
|
CVE-2019-13650
|
2024-11-21 13:25 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223766
|
9.8 |
CRITICAL
Network
|
tp-link
|
m7350_firmware
|
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).
|
CWE-78
OS Command
|
CVE-2019-13649
|
2024-11-21 13:25 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223767
|
7.8 |
HIGH
Local
|
hornerautomation
|
cscape
|
In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13545
|
2024-11-21 13:25 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223768
|
7.8 |
HIGH
Local
|
hornerautomation
|
cscape
|
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an a…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13541
|
2024-11-21 13:25 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223769
|
8.8 |
HIGH
Network
|
broadcom
|
ca_performance_management network_operations
|
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise syste…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13657
|
2024-11-21 13:25 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223770
|
6.5 |
MEDIUM
Network
|
siemens
|
simatic_it_uadm
|
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a pass…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-13929
|
2024-11-21 13:25 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|