|
218591
|
7.5 |
HIGH
Network
|
bevywise
|
mqttroute
|
In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be used to cause a Denial of Service attack against the broker.
|
NVD-CWE-noinfo
|
CVE-2019-6241
|
2024-11-21 13:46 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218592
|
7.8 |
HIGH
Local
|
panasonic
|
control_fpwin_pro
|
Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user triggering incompatible type errors because the resource does not have expect…
|
CWE-843
Type Confusion
|
CVE-2019-6532
|
2024-11-21 13:46 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218593
|
7.8 |
HIGH
Local
|
panasonic
|
control_fpwin_pro
|
Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer overflows, which may lead to remote code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6530
|
2024-11-21 13:46 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218594
|
8.8 |
HIGH
Network
|
kyocera
|
command_center_rx
|
Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a cleartext FTP or SMB password.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-6452
|
2024-11-21 13:46 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218595
|
7.5 |
HIGH
Network
|
soyal
|
ar-727h_firmware ar-829ev5_firmware
|
On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-6451
|
2024-11-21 13:46 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218596
|
4.7 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6588
|
2024-11-21 13:46 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218597
|
6.8 |
MEDIUM
Network
|
hp
|
z4_g4_workstation_firmware z4_g4_core-x_workstation_firmware z6_g4_workstation_firmware z8_g4_workstation_firmware
|
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates…
|
CWE-667
Improper Locking
|
CVE-2019-6322
|
2024-11-21 13:46 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218598
|
7.2 |
HIGH
Network
|
hp
|
z4_g4_workstation_firmware z4_g4_core-x_workstation_firmware z6_g4_workstation_firmware z8_g4_workstation_firmware
|
HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates…
|
CWE-667
Improper Locking
|
CVE-2019-6321
|
2024-11-21 13:46 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218599
|
5.4 |
MEDIUM
Network
|
wso2
|
api_manager
|
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-6513
|
2024-11-21 13:46 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218600
|
7.5 |
HIGH
Network
|
siemens
|
sinamics_perfect_harmony_gh180_with_nxg_i_control_mlfb_6sr2_firmware sinamics_perfect_harmony_gh180_with_nxg_i_control_mlfb_6sr3_firmware sinamics_perfect_harmony_gh180_with_nxg_i_control_mlfb_…
|
A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G28), SINAMICS PERFECT HARMONY GH180 with NXG I…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-6578
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|