CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2019-18525

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18526

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18472

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18483

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18471

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18482

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18467

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18468

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18469

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18470

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18473

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18474

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18475

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18476

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18477

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18478

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18479

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18480

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18481

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18484

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18485

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2019-18486

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 28 Oct 2019
    6.1
    Medium

    CVE-2010-4245

    Last Modified: 21 Nov 2024

    pootle 2.0.5 has XSS via 'match_names' parameter

    Published: 28 Oct 2019
    5.3
    Medium

    CVE-2019-17224

    Last Modified: 21 Nov 2024

    The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal attack, which can be exploited in order to test for the existence of a file pathname outside of the web root directory. If a file exists but is not part of the product, there is a 404 error. If a file does not exist, there is a 302 redirect to index.html.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-3636

    Last Modified: 21 Nov 2024

    A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.

    Published: 28 Oct 2019
    6.1
    Medium

    CVE-2009-4900

    Last Modified: 21 Nov 2024

    pixelpost 1.7.1 has XSS

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2009-4899

    Last Modified: 21 Nov 2024

    pixelpost 1.7.1 has SQL injection

    Published: 28 Oct 2019
    5.5
    Medium

    CVE-2010-3293

    Last Modified: 21 Nov 2024

    mailscanner can allow local users to prevent virus signatures from being updated

    Published: 28 Oct 2019
    4.4
    Medium

    CVE-2020-10773

    Last Modified: 21 Nov 2024

    A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.

    Published: 28 Oct 2019
    8.8
    High

    CVE-2019-18195

    Last Modified: 21 Nov 2024

    An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2005-2349

    Last Modified: 20 Nov 2024

    Zoo 2.10 has Directory traversal

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2002-2444

    Last Modified: 20 Nov 2024

    Snoopy before 2.0.0 has a security hole in exec cURL

    Published: 28 Oct 2019
    6.5
    Medium

    CVE-2019-14925

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-14929

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-14930

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the accounts ineaadmin and mitsadmin are able to escalate privileges to root without supplying a password due to insecure entries in /etc/sudoers on the RTU.)

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-14926

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial installation or with firmware updates. In other words, these devices use private-key values in /etc/ssh/ssh_host_rsa_key, /etc/ssh/ssh_host_ecdsa_key, and /etc/ssh/ssh_host_dsa_key files that are publicly available from the vendor web sites.

    Published: 28 Oct 2019
    5.4
    Medium

    CVE-2019-14928

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-14927

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-14931

    Last Modified: 21 Nov 2024

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

    Published: 28 Oct 2019
    8.8
    High

    CVE-2019-16663

    Last Modified: 21 Nov 2024

    An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.

    Published: 28 Oct 2019
    9.8
    Critical

    CVE-2019-16662

    Last Modified: 21 Nov 2024

    An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-18812

    Last Modified: 21 Nov 2024

    A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-c0a333d842ef.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0552

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0509

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0579

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0580

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0581

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0582

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0585

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019
    —
    Unknown

    CVE-2020-0589

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 28 Oct 2019