|
218701
|
9.8 |
CRITICAL
Network
|
kddi
|
smart_tv_box_firmware
|
Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary operations on the device without user's intent, such as installing arbitrary soft…
|
NVD-CWE-noinfo
|
CVE-2019-6005
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218702
|
6.1 |
MEDIUM
Network
|
fujixerox
|
apeosware_management_suite apeosware_management_suite_2
|
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web …
|
CWE-601
Open Redirect
|
CVE-2019-6004
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218703
|
6.1 |
MEDIUM
Network
|
ec-cube
|
amazon_pay
|
Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6003
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218704
|
8.8 |
HIGH
Network
|
panasonic
|
video_insight_vms
|
SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2019-5996
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218705
|
8.8 |
HIGH
Network
|
tipsandtricks-hq
|
category_specific_rss_feed_subscription
|
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecif…
|
CWE-352
Origin Validation Error
|
CVE-2019-5993
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218706
|
8.8 |
HIGH
Network
|
ultra-prod
|
wordpress_ultra_simple_paypal_shopping_cart
|
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified …
|
CWE-352
Origin Validation Error
|
CVE-2019-5992
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218707
|
7.6 |
HIGH
Network
|
cybozu
|
garoon
|
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2019-5991
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218708
|
8.8 |
HIGH
Network
|
ntt-east ntt-west
|
pr-s300ne_firmware rt-s300ne_firmware rv-s340ne_firmware pr-s300hi_firmware rt-s300hi_firmware rv-s340hi_firmware pr-s300se_firmware rt-s300se_firmware rv-s340se_firmware p…
|
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/R…
|
CWE-352
Origin Validation Error
|
CVE-2019-5986
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218709
|
6.1 |
MEDIUM
Network
|
ntt-east ntt-west
|
pr-s300ne_firmware rt-s300ne_firmware rv-s340ne_firmware pr-s300hi_firmware rt-s300hi_firmware rv-s340hi_firmware pr-s300se_firmware rt-s300se_firmware rv-s340se_firmware p…
|
Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firm…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5985
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218710
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
|
CWE-601
Open Redirect
|
CVE-2019-5978
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|