|
223321
|
9.8 |
CRITICAL
Network
|
raonwiz
|
dext5
|
Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex metho…
|
NVD-CWE-noinfo
|
CVE-2019-19168
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223322
|
9.8 |
CRITICAL
Network
|
tobesoft
|
nexacro
|
Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execut…
|
NVD-CWE-noinfo
|
CVE-2019-19167
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223323
|
7.8 |
HIGH
Local
|
tobesoft
|
xplatform
|
Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code execution.
|
NVD-CWE-noinfo
|
CVE-2019-19166
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223324
|
8.8 |
HIGH
Network
|
intelbras
|
action_rf_1200_firmware
|
Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
|
CWE-352
Origin Validation Error
|
CVE-2019-19517
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223325
|
6.1 |
MEDIUM
Network
|
ayision
|
ays-wr01_firmware
|
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19515
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223326
|
5.4 |
MEDIUM
Network
|
ayision
|
ays-wr01_firmware
|
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19514
|
2024-11-21 13:34 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223327
|
8.8 |
HIGH
Network
|
bmcsoftware
|
control-m\/agent
|
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
|
CWE-78
OS Command
|
CVE-2019-19220
|
2024-11-21 13:34 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223328
|
7.5 |
HIGH
Network
|
bmcsoftware
|
control-m\/agent
|
BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.
|
NVD-CWE-noinfo
|
CVE-2019-19219
|
2024-11-21 13:34 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223329
|
7.5 |
HIGH
Network
|
bmcsoftware
|
control-m\/agent
|
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
|
CWE-522 CWE-732
Insufficiently Protected Credentials Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19218
|
2024-11-21 13:34 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223330
|
8.8 |
HIGH
Network
|
bmcsoftware
|
control-m\/agent
|
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
|
CWE-78
OS Command
|
CVE-2019-19217
|
2024-11-21 13:34 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|