|
221991
|
6.5 |
MEDIUM
Network
|
osisoft
|
pi_vision
|
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauthorized tag data when viewing analysis data referen…
|
NVD-CWE-Other
|
CVE-2019-18275
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221992
|
4.8 |
MEDIUM
Network
|
osisoft
|
pi_vision
|
OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripting, which may allow invalid input to be introduced.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18273
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221993
|
8.8 |
HIGH
Network
|
osisoft
|
pi_vision
|
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.
|
CWE-352
Origin Validation Error
|
CVE-2019-18271
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221994
|
4.7 |
MEDIUM
Local
|
osisoft
|
pi_vision
|
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision. T…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-18244
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221995
|
7.8 |
HIGH
Local
|
totalav
|
totalav_2020
|
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.
|
NVD-CWE-noinfo
|
CVE-2019-18194
|
2024-11-21 13:32 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221996
|
4.3 |
MEDIUM
Network
|
otrs debian opensuse
|
otrs debian_linux leap backports_sle
|
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent…
|
NVD-CWE-noinfo
|
CVE-2019-18179
|
2024-11-21 13:32 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221997
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-859_firmware dir-822_firmware dir-823_firmware dir-865l_firmware dir-868l_firmware dir-869_firmware dir-880l_firmware dir-890l_firmware dir-890r_firmware dir-885l_firmw…
|
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted…
|
CWE-78
OS Command
|
CVE-2019-17621
|
2024-11-21 13:32 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221998
|
6.1 |
MEDIUM
Network
|
reliablecontrols
|
mach-prowebsys_firmware mach-prowebcom_firmware
|
Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18249
|
2024-11-21 13:32 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221999
|
8.8 |
HIGH
Network
|
orckestra
|
c1_cms
|
An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbit…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18211
|
2024-11-21 13:32 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222000
|
7.8 |
HIGH
Local
|
we-con
|
plc_editor
|
Multiple buffer overflow vulnerabilities exist when the PLC Editor Version 1.3.5_20190129 processes project files. An attacker could use a specially crafted project file to exploit and execute code u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-18236
|
2024-11-21 13:32 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|