|
223261
|
6.5 |
MEDIUM
Network
|
mitsubishielectric inea
|
smartrtu_firmware me-rtu_firmware
|
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the …
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14925
|
2024-11-21 13:27 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223262
|
9.8 |
CRITICAL
Network
|
mitsubishielectric inea
|
smartrtu_firmware me-rtu_firmware
|
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclo…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-14926
|
2024-11-21 13:27 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223263
|
9.8 |
CRITICAL
Network
|
hinet
|
gpon_firmware
|
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 6998. CVSS 3.0 Base score 10.0. CVSS vector: …
|
NVD-CWE-noinfo
|
CVE-2019-15066
|
2024-11-21 13:27 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223264
|
7.5 |
HIGH
Network
|
hinet
|
gpon_firmware
|
A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0…
|
NVD-CWE-noinfo
|
CVE-2019-15065
|
2024-11-21 13:27 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223265
|
9.8 |
CRITICAL
Network
|
hinet
|
gpon_firmware
|
HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15064
|
2024-11-21 13:27 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223266
|
7.5 |
HIGH
Network
|
redhat
|
keycloak
|
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could …
|
CWE-863
Incorrect Authorization
|
CVE-2019-14832
|
2024-11-21 13:27 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223267
|
7.8 |
HIGH
Local
|
ubisoft
|
uplay
|
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-14737
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223268
|
4.9 |
MEDIUM
Network
|
redhat
|
wildfly_core jboss_enterprise_application_platform single_sign-on data_grid
|
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
|
CWE-269
Improper Privilege Management
|
CVE-2019-14838
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223269
|
7.4 |
HIGH
Network
|
jss_cryptomanager_project redhat
|
jss_cryptomanager enterprise_linux enterprise_linux_desktop enterprise_linux_eus enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_…
|
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. …
|
-
|
CVE-2019-14823
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223270
|
5.5 |
MEDIUM
Local
|
redhat
|
ansible_engine ansible_tower
|
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name t…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-14858
|
2024-11-21 13:27 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|