|
223591
|
9.8 |
CRITICAL
Network
|
mysyngeryss
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (CWE-306) vulnerability. The affected product does n…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16879
|
2024-11-21 13:31 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223592
|
6.1 |
MEDIUM
Network
|
mageewp
|
onetone
|
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17231
|
2024-11-21 13:31 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223593
|
5.3 |
MEDIUM
Network
|
mageewp
|
onetone
|
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
|
NVD-CWE-noinfo
|
CVE-2019-17230
|
2024-11-21 13:31 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223594
|
7.5 |
HIGH
Network
|
freeradius opensuse
|
freeradius leap
|
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting i…
|
CWE-662
Improper Synchronization
|
CVE-2019-17185
|
2024-11-21 13:31 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223595
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox thunderbird firefox_esr ubuntu_linux
|
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability aff…
|
CWE-843
Type Confusion
|
CVE-2019-17026
|
2024-11-21 13:31 |
2020-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223596
|
6.1 |
MEDIUM
Network
|
stylemixthemes
|
motors_-_car_dealer\ _classifieds_\&_listing
|
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17229
|
2024-11-21 13:31 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223597
|
6.5 |
MEDIUM
Network
|
stylemixthemes
|
motors_-_car_dealer\ _classifieds_\&_listing
|
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-17228
|
2024-11-21 13:31 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223598
|
9.4 |
CRITICAL
Network
|
netgear
|
ac1200_r6220_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not requ…
|
NVD-CWE-Other
|
CVE-2019-17137
|
2024-11-21 13:31 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223599
|
6.5 |
MEDIUM
Adjacent
|
cypress
|
psoc_4_ble
|
The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a p…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17061
|
2024-11-21 13:31 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223600
|
6.5 |
MEDIUM
Adjacent
|
nxp
|
mcuxpresso_software_development_kit
|
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer hea…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17060
|
2024-11-21 13:31 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|