• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-18253
Abb, Relion 670 Firmware
Pm554-tp-eth_firmware, Pm554-tp-eth, Cp651_firmware, Cp651, Cp651-web_firmware, Cp651-web, Cp661-web_firmware, Cp661-web, Cp661_firmware, Cp661
2019-12-17
N/A
10 CRITICAL
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
CVE-2019-18252
Biotronik, Cardiomessenger Ii-s T-line, Cardiomessenger Ii-s T-line Firmware
Cardiomessenger_ii-s_gsm_firmware, Cardiomessenger_ii-s_gsm, Cardiomessenger_ii-s_t-line_firmware, Cardiomessenger_ii-s_t-line
2021-04-06
N/A
4.3 MEDIUM
BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remote Communication infrastructure.
CVE-2019-18251
2019-12-11
N/A
8.8 HIGH
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.
CVE-2019-18250
2021-10-29
N/A
9.8 CRITICAL
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.
CVE-2019-1825
2019-10-09
N/A
8.1 HIGH
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains malicious SQL statements to the affected application. A successful exploit could allow the attacker to view or modify entries in some database tables, affecting the integrity of the data.
CVE-2019-18249
Mach-prowebsys Firmware, Reliablecontrols
Mach-prowebsys_firmware, Mach-prowebsys, Mach-prowebcom_firmware, Mach-prowebcom
2020-01-07
N/A
6.1 MEDIUM
Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on a malicious link.
CVE-2019-18248
Biotronik, Cardiomessenger Ii-s T-line, Cardiomessenger Ii-s T-line Firmware
Cardiomessenger_ii-s_gsm_firmware, Cardiomessenger_ii-s_gsm, Cardiomessenger_ii-s_t-line_firmware, Cardiomessenger_ii-s_t-line
2021-04-06
N/A
4.3 MEDIUM
BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to the BIOTRONIK Remote Communication infrastructure.
CVE-2019-18247
Abb, Relion 670 Firmware
Pm554-tp-eth_firmware, Pm554-tp-eth, Cp651_firmware, Cp651, Cp651-web_firmware, Cp651-web, Cp661-web_firmware, Cp661-web, Cp661_firmware, Cp661
2019-12-11
N/A
7.5 HIGH
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.
CVE-2019-18246
Biotronik, Cardiomessenger Ii-s T-line, Cardiomessenger Ii-s T-line Firmware
Cardiomessenger_ii-s_gsm_firmware, Cardiomessenger_ii-s_gsm, Cardiomessenger_ii-s_t-line_firmware, Cardiomessenger_ii-s_t-line
2021-04-06
N/A
4.3 MEDIUM
BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.
CVE-2019-18245
2019-12-17
N/A
7.8 HIGH
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.
« Previous 1 … 5,904 5,905 5,906 5,907 5,908 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE