• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-11528
Softing, Uagate Si, Uagate Si Firmware
Uagate_si_firmware, Uagate_si, Uagate_mb_firmware, Uagate_mb, Uagate_840d_firmware, Uagate_840d
2021-07-21
N/A
7.5 HIGH
An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.
CVE-2019-11527
Softing, Uagate Si, Uagate Si Firmware
Uagate_si_firmware, Uagate_si, Uagate_mb_firmware, Uagate_mb, Uagate_840d_firmware, Uagate_840d
2019-10-15
N/A
8.8 HIGH
An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.
CVE-2019-11526
Softing, Uagate Si, Uagate Si Firmware
Uagate_si_firmware, Uagate_si, Uagate_mb_firmware, Uagate_mb, Uagate_840d_firmware, Uagate_840d
2021-07-21
N/A
9.8 CRITICAL
An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.
CVE-2019-11523
Anviz, M3
M3_firmware, M3
2020-08-24
N/A
9.8 CRITICAL
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).
CVE-2019-11522
2019-08-23
N/A
5.4 MEDIUM
OX App Suite 7.10.0 to 7.10.2 allows XSS.
CVE-2019-11521
2020-08-24
N/A
8.1 HIGH
OX App Suite 7.10.1 allows Content Spoofing.
CVE-2019-1152
2020-08-24
N/A
8.8 HIGH
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1144, CVE-2019-1145, CVE-2019-1149, CVE-2019-1150, CVE-2019-1151.
CVE-2019-11519
2019-05-01
N/A
4.9 MEDIUM
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
CVE-2019-11518
2019-04-27
N/A
7.2 HIGH
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete.
CVE-2019-11517
2019-06-11
N/A
6.5 MEDIUM
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.
« Previous 1 … 6,463 6,464 6,465 6,466 6,467 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE