• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-18267
Ge, S2020g, S2020g Firmware
Aestiva_7100_firmware, Aestiva_7100, Aestiva_7900_firmware, Aestiva_7900, Aespire_7100_firmware, Aespire_7100, Aespire_7900_firmware, Aespire_7900, S2020_firmware, S2020
2020-01-07
N/A
5.4 MEDIUM
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
CVE-2019-18265
Digitalalertsystems, One-net Se Firmware
Dasdec_ii_firmware, Dasdec_ii, One-net_se_firmware, One-net_se, Dasdec_i_firmware, Dasdec_i, One-net_firmware, One-net, Dasdec_iii_firmware, Dasdec_iii
2022-12-09
N/A
5.4 MEDIUM
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.
CVE-2019-18263
Philips, Veradius Unity Firmware
Hdi_4000_firmware, Hdi_4000, Intellivue_mp_monitors_mp20-mp90_firmware, M80010a, M8001a, M8002a, M8003a, M8004a, M8005a, M8007a
2020-01-10
N/A
6.5 MEDIUM
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018). The router software uses an encryption scheme that is not strong enough for the level of protection required.
CVE-2019-18261
2019-12-27
N/A
9.8 CRITICAL
In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.
CVE-2019-1826
Aironet Access Point Firmware, Cisco
Sd-wan_firmware, Vedge-100, Vedge-1000, Vedge-100b, Vedge-2000, Vedge-5000, Vedge_100m, Vedge_100wm, Hyperflex_hx220c_m5_firmware, Hyperflex_hx220c_m5
2019-10-09
N/A
5.7 MEDIUM
A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation on QoS fields within Wi-Fi frames by the affected device. An attacker could exploit this vulnerability by sending malformed Wi-Fi frames to an affected device. A successful exploit could allow the attacker to cause the affected device to crash, resulting in a DoS condition.
CVE-2019-18259
2019-12-27
N/A
9.8 CRITICAL
In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.
CVE-2019-18257
2020-10-22
N/A
9.8 CRITICAL
In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.
CVE-2019-18256
Biotronik, Cardiomessenger Ii-s T-line, Cardiomessenger Ii-s T-line Firmware
Cardiomessenger_ii-s_gsm_firmware, Cardiomessenger_ii-s_gsm, Cardiomessenger_ii-s_t-line_firmware, Cardiomessenger_ii-s_t-line
2021-10-29
N/A
4.6 MEDIUM
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.
CVE-2019-18255
2021-02-24
N/A
5.5 MEDIUM
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.
CVE-2019-18254
Biotronik, Cardiomessenger Ii-s T-line, Cardiomessenger Ii-s T-line Firmware
Cardiomessenger_ii-s_gsm_firmware, Cardiomessenger_ii-s_gsm, Cardiomessenger_ii-s_t-line_firmware, Cardiomessenger_ii-s_t-line
2021-10-29
N/A
4.6 MEDIUM
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with.
« Previous 1 … 5,903 5,904 5,905 5,906 5,907 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE