|
218661
|
7.2 |
HIGH
Network
|
kunbus
|
pr100088_modbus_gateway_firmware
|
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-6549
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218662
|
9.1 |
CRITICAL
Network
|
kunbus
|
pr100088_modbus_gateway_firmware
|
Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-6533
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218663
|
9.8 |
CRITICAL
Network
|
kunbus
|
pr100088_modbus_gateway_firmware
|
PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged i…
|
CWE-287
Improper Authentication
|
CVE-2019-6527
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218664
|
5.3 |
MEDIUM
Network
|
lexmark
|
xm5163_firmware xm5170_firmware xm7155_firmware xm7163_firmware xm7170_firmware xm7155x_firmware xm7163x_firmware xm7170x_firmware cx310_firmware cx410_firmware cx510_fi…
|
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.
|
NVD-CWE-noinfo
|
CVE-2019-6489
|
2024-11-21 13:46 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218665
|
7.2 |
HIGH
Network
|
kentico
|
kentico
|
Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vul…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-6242
|
2024-11-21 13:46 |
2019-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218666
|
9.8 |
CRITICAL
Network
|
forcepoint
|
user_id
|
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of this vulnerability may lead to remote code execution…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-6139
|
2024-11-21 13:46 |
2019-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218667
|
6.8 |
MEDIUM
Physics
|
bd
|
facslyric_ivd facslyric
|
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Professional Operating S…
|
NVD-CWE-Other
|
CVE-2019-6517
|
2024-11-21 13:46 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218668
|
6.1 |
MEDIUM
Network
|
broadcom
|
automic_workload_automation
|
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attac…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6504
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218669
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess\/scada
|
WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.
|
CWE-89
SQL Injection
|
CVE-2019-6523
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218670
|
8.6 |
HIGH
Network
|
advantech
|
webaccess\/scada
|
WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information.
|
CWE-287
Improper Authentication
|
CVE-2019-6521
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|