|
219341
|
5.9 |
MEDIUM
Network
|
citrix
|
netscaler_gateway_firmware netscaler_application_delivery_controller_firmware
|
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 b…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-6485
|
2024-11-21 13:46 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219342
|
8.1 |
HIGH
Network
|
drupal
|
drupal
|
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-6340
|
2024-11-21 13:46 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219343
|
8.1 |
HIGH
Network
|
mirc
|
mirc
|
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC …
|
CWE-88
Argument Injection
|
CVE-2019-6453
|
2024-11-21 13:46 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219344
|
6.1 |
MEDIUM
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Ma…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6589
|
2024-11-21 13:46 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219345
|
7.5 |
HIGH
Network
|
aveva
|
indusoft_web_studio intouch_machine_edition_2014
|
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a speci…
|
NVD-CWE-Other
|
CVE-2019-6545
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219346
|
9.8 |
CRITICAL
Network
|
aveva
|
indusoft_web_studio intouch_machine_edition_2014
|
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-6543
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219347
|
7.8 |
HIGH
Local
|
we-con
|
levistudiou
|
A memory corruption vulnerability has been identified in WECON LeviStudioU version 1.8.56 and prior, which may allow arbitrary code execution. Mat Powell, Ziad Badawi, and Natnael Samson working with…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6541
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219348
|
7.8 |
HIGH
Local
|
we-con
|
levistudiou
|
Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitrary code execution. Mat Powell, Ziad Badawi, and Natnael S…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6539
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219349
|
7.8 |
HIGH
Local
|
we-con
|
levistudiou
|
Multiple stack-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior may be exploited when parsing strings within project files. The process does not properly validate t…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6537
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219350
|
7.2 |
HIGH
Network
|
kunbus
|
pr100088_modbus_gateway_firmware
|
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-6549
|
2024-11-21 13:46 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|