|
224791
|
6.7 |
MEDIUM
Local
|
netatmo
|
smart_indoor_camera_firmware
|
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart Indoor Camera allows an attacker to execute comma…
|
CWE-77
Command Injection
|
CVE-2019-17101
|
2024-11-21 13:31 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224792
|
9.8 |
CRITICAL
Network
|
mysyngeryss
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (CWE-306) vulnerability. The affected product does n…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16879
|
2024-11-21 13:31 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224793
|
6.1 |
MEDIUM
Network
|
mageewp
|
onetone
|
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17231
|
2024-11-21 13:31 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224794
|
5.3 |
MEDIUM
Network
|
mageewp
|
onetone
|
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
|
NVD-CWE-noinfo
|
CVE-2019-17230
|
2024-11-21 13:31 |
2020-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224795
|
7.5 |
HIGH
Network
|
freeradius opensuse
|
freeradius leap
|
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting i…
|
CWE-662
Improper Synchronization
|
CVE-2019-17185
|
2024-11-21 13:31 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224796
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox thunderbird firefox_esr ubuntu_linux
|
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability aff…
|
CWE-843
Type Confusion
|
CVE-2019-17026
|
2024-11-21 13:31 |
2020-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224797
|
6.1 |
MEDIUM
Network
|
stylemixthemes
|
motors_-_car_dealer\ _classifieds_\&_listing
|
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17229
|
2024-11-21 13:31 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224798
|
6.5 |
MEDIUM
Network
|
stylemixthemes
|
motors_-_car_dealer\ _classifieds_\&_listing
|
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-17228
|
2024-11-21 13:31 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224799
|
9.4 |
CRITICAL
Network
|
netgear
|
ac1200_r6220_firmware
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not requ…
|
NVD-CWE-Other
|
CVE-2019-17137
|
2024-11-21 13:31 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224800
|
6.5 |
MEDIUM
Adjacent
|
cypress
|
psoc_4_ble
|
The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a p…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17061
|
2024-11-21 13:31 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|