|
218671
|
7.5 |
HIGH
Network
|
enttec
|
datagate_mk2_firmware storm_24_firmware pixelator_firmware
|
ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to initiate a remote reboot, which may be used to cause …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-6542
|
2024-11-21 13:46 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218672
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6536
|
2024-11-21 13:46 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218673
|
9.1 |
CRITICAL
Network
|
siemens
|
scalance_x-200_firmware scalance_x-300_firmware scalance_xp-200_firmware scalance_xc-200_firmware scalance_xf-200_firmware
|
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious …
|
-
|
CVE-2019-6569
|
2024-11-21 13:46 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218674
|
6.5 |
MEDIUM
Adjacent
|
medtronic
|
mycarelink_monitor_24950_firmware mycarelink_monitor_24952_firmware carelink_monitor_2490c_firmware carelink_2090_firmware amplia_crt-d_firmware claria_crt-d_firmware compia_crt-d_f…
|
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-6540
|
2024-11-21 13:46 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218675
|
5.4 |
MEDIUM
Network
|
drupal debian fedoraproject
|
drupal debian_linux fedora
|
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a …
|
CWE-79
Cross-site Scripting
|
CVE-2019-6341
|
2024-11-21 13:46 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218676
|
6.5 |
MEDIUM
Adjacent
|
medtronic
|
mycarelink_monitor_firmware carelink_monitor_firmware carelink_2090_firmware amplia_crt-d_firmware claria_crt-d_firmware compia_crt-d_firmware concerto_crt-d_firmware concerto_ii…
|
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-…
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2019-6538
|
2024-11-21 13:46 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218677
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2019-6240
|
2024-11-21 13:46 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218678
|
8.8 |
HIGH
Network
|
risi
|
gestao_de_horarios
|
RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-6491
|
2024-11-21 13:46 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218679
|
9.8 |
CRITICAL
Network
|
blogengine
|
blogengine.net
|
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx componen…
|
CWE-22
Path Traversal
|
CVE-2019-6714
|
2024-11-21 13:46 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218680
|
5.9 |
MEDIUM
Network
|
mastercard
|
qkr\!_with_masterpass
|
The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obsolete versions from 2016 or earlier.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-6702
|
2024-11-21 13:46 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|