|
218671
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess\/scada
|
WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker to upload malicious data.
|
CWE-287
Improper Authentication
|
CVE-2019-6519
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218672
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager
|
On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume excessive resources when processing SSL Session ID Persistence traffic.
|
NVD-CWE-noinfo
|
CVE-2019-6590
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218673
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
q03udvcpu_firmware q04udvcpu_firmware q06udvcpu_firmware q13udvcpu_firmware q26udvcpu_firmware q04udpvcpu_firmware q06udpvcpu_firmware q13udpvcpu_firmware q26udpvcpu_firmware<…
|
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-6535
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218674
|
5.4 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when …
|
CWE-79
Cross-site Scripting
|
CVE-2019-6591
|
2024-11-21 13:46 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218675
|
9.8 |
CRITICAL
Network
|
schedmd opensuse
|
slurm leap
|
SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
|
NVD-CWE-noinfo
|
CVE-2019-6438
|
2024-11-21 13:46 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218676
|
9.8 |
CRITICAL
Network
|
calmar-webmedia
|
total_donations
|
Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option va…
|
NVD-CWE-noinfo
|
CVE-2019-6703
|
2024-11-21 13:46 |
2019-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218677
|
8.2 |
HIGH
Network
|
golang debian opensuse
|
go debian_linux leap
|
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recove…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6486
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218678
|
9.8 |
CRITICAL
Network
|
thinkcmf
|
thinkcmf
|
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code int…
|
CWE-94
Code Injection
|
CVE-2019-6713
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218679
|
7.2 |
HIGH
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6708
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218680
|
7.2 |
HIGH
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6707
|
2024-11-21 13:46 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|