• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-18998
2022-01-01
N/A
7.1 HIGH
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.
CVE-2019-18997
Abb, Pb610 Panel Builder 600
Pm554-tp-eth_firmware, Pm554-tp-eth, Cp651_firmware, Cp651, Cp651-web_firmware, Cp651-web, Cp661-web_firmware, Cp661-web, Cp661_firmware, Cp661
2020-10-22
N/A
7.5 HIGH
The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.
CVE-2019-18996
Abb, Pb610 Panel Builder 600
Pm554-tp-eth_firmware, Pm554-tp-eth, Cp651_firmware, Cp651, Cp651-web_firmware, Cp651-web, Cp661-web_firmware, Cp661-web, Cp661_firmware, Cp661
2023-02-03
N/A
7.8 HIGH
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.
CVE-2019-18995
Abb, Pb610 Panel Builder 600
Pm554-tp-eth_firmware, Pm554-tp-eth, Cp651_firmware, Cp651, Cp651-web_firmware, Cp651-web, Cp661-web_firmware, Cp661-web, Cp661_firmware, Cp661
2019-12-31
N/A
5.3 MEDIUM
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
CVE-2019-18994
Abb, Pb610 Panel Builder 600
Pm554-tp-eth_firmware, Pm554-tp-eth, Cp651_firmware, Cp651, Cp651-web_firmware, Cp651-web, Cp661-web_firmware, Cp661-web, Cp661_firmware, Cp661
2019-12-31
N/A
6.5 MEDIUM
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.
CVE-2019-18993
2019-12-16
N/A
5.4 MEDIUM
OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).
CVE-2019-18992
2019-12-16
N/A
5.4 MEDIUM
OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).
CVE-2019-18991
Atheros Ar9285 Firmware, Qualcomm
Apq8009_firmware, Apq8009, Apq8017_firmware, Apq8017, Apq8053_firmware, Apq8053, Apq8096au_firmware, Apq8096au, Apq8098_firmware, Apq8098
2021-07-21
N/A
5.4 MEDIUM
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.
CVE-2019-18990
Realtek, Rtl8881an Firmware
Rtl8812ar_firmware, Rtl8812ar, Rtl8196d_firmware, Rtl8196d, Rtl8192er_firmware, Rtl8192er, Rtl8881an_firmware, Rtl8881an, Rtk_11n_ap_firmware, Rtk_11n_ap
2021-07-21
N/A
5.4 MEDIUM
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.
CVE-2019-1899
Cisco, Rv215w, Rv215w Firmware
Sd-wan_firmware, Vedge-100, Vedge-1000, Vedge-100b, Vedge-2000, Vedge-5000, Vedge_100m, Vedge_100wm, Hyperflex_hx220c_m5_firmware, Hyperflex_hx220c_m5
2020-10-16
N/A
5.3 MEDIUM
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.
« Previous 1 … 5,834 5,835 5,836 5,837 5,838 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE