|
247671
|
8.1 |
HIGH
Network
|
deltaww
|
screeneditor cncsoft
|
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing pr…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10598
|
2024-11-21 12:41 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247672
|
6.1 |
MEDIUM
Network
|
edimax
|
edimax_ew-7438rpn_v2_firmware
|
An issue was discovered in Edimax EW-7438RPn Mini v2 before version 1.26. There is XSS in an SSID field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10569
|
2024-11-21 12:41 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247673
|
9.8 |
CRITICAL
Network
|
crestron
|
tsw-x60_firmware mc3_firmware
|
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need …
|
CWE-287
Improper Authentication
|
CVE-2018-10630
|
2024-11-21 12:41 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247674
|
4.4 |
MEDIUM
Adjacent
|
medtronic
|
mycarelink_24952_patient_monitor_firmware mycarelink_24950_patient_monitor_firmware
|
A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2018-10626
|
2024-11-21 12:41 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247675
|
7.1 |
HIGH
Physics
|
medtronic
|
mycarelink_24952_patient_monitor_firmware mycarelink_24950_patient_monitor_firmware
|
A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected products use per-product credentials that are stored in a recoverable format. An a…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-10622
|
2024-11-21 12:41 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247676
|
6.5 |
MEDIUM
Adjacent
|
johnsoncontrols
|
bcpro metasys_system
|
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the se…
|
CWE-388
7PK - Errors
|
CVE-2018-10624
|
2024-11-21 12:41 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247677
|
9.8 |
CRITICAL
Network
|
davolink
|
dvw-3200n_firmware
|
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2018-10618
|
2024-11-21 12:41 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247678
|
6.1 |
MEDIUM
Network
|
martem
|
telem-gwm_firmware telem-gw6_firmware
|
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code e…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10609
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247679
|
7.5 |
HIGH
Network
|
martem
|
telem-gwm_firmware telem-gw6_firmware
|
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a deni…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-10607
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247680
|
9.8 |
CRITICAL
Network
|
martem
|
telem-gwm_firmware telem-gw6_firmware
|
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the …
|
CWE-287
Improper Authentication
|
CVE-2018-10603
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|