|
218601
|
5.4 |
MEDIUM
Network
|
siemens
|
simatic_hmi_comfort_panels_firmware simatic_hmi_comfort_outdoor_panels_firmware simatic_hmi_ktp_mobile_panels_ktp400f_firmware simatic_hmi_ktp_mobile_panels_ktp700_firmware simatic_hmi_kt…
|
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KT…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6577
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218602
|
7.5 |
HIGH
Network
|
siemens
|
simatic_hmi_comfort_panels_firmware simatic_hmi_comfort_outdoor_panels_firmware simatic_hmi_ktp_mobile_panels_ktp400f_firmware simatic_hmi_ktp_mobile_panels_ktp700_firmware simatic_hmi_kt…
|
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KT…
|
CWE-310
Cryptographic Issues
|
CVE-2019-6576
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218603
|
7.5 |
HIGH
Network
|
siemens
|
sinamics_perfect_harmony_gh180_with_nxg_i_control_mlfb_6sr2_firmware sinamics_perfect_harmony_gh180_with_nxg_i_control_mlfb_6sr3_firmware sinamics_perfect_harmony_gh180_with_nxg_i_control_mlfb_…
|
A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or …
|
NVD-CWE-noinfo
|
CVE-2019-6574
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218604
|
9.1 |
CRITICAL
Network
|
siemens
|
simatic_hmi_comfort_panels_firmware simatic_hmi_comfort_outdoor_panels_firmware simatic_hmi_ktp_mobile_panels_ktp400f_firmware simatic_hmi_ktp_mobile_panels_ktp700_firmware simatic_hmi_kt…
|
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KT…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-6572
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218605
|
5.8 |
MEDIUM
Network
|
wso2
|
dashboard_server
|
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent wor…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-6516
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218606
|
5.3 |
MEDIUM
Network
|
wso2
|
api_manager
|
An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.
|
NVD-CWE-noinfo
|
CVE-2019-6515
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218607
|
4.8 |
MEDIUM
Network
|
wso2
|
dashboard_server
|
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6514
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218608
|
4.1 |
MEDIUM
Network
|
wso2
|
api_manager
|
An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the internal workstation (SSRF port-scanning), other adjacent workstations (SSRF netw…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-6512
|
2024-11-21 13:46 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218609
|
7.8 |
HIGH
Local
|
ge
|
ge_communicator
|
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to…
|
NVD-CWE-Other
|
CVE-2019-6566
|
2024-11-21 13:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218610
|
7.8 |
HIGH
Local
|
ge
|
ge_communicator
|
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-6564
|
2024-11-21 13:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|