|
249901
|
9.8 |
CRITICAL
Network
|
codesys
|
control_for_beaglebone_sl control_for_empc-a\/imx6_sl control_for_iot2000_sl control_for_linux_sl control_for_pfc100_sl control_for_pfc200_sl control_for_raspberry_pi_sl control_…
|
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker…
|
CWE-311 CWE-732
Missing Encryption of Sensitive Data Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10612
|
2024-11-21 12:41 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249902
|
7.2 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary co…
|
CWE-78
OS Command
|
CVE-2018-10587
|
2024-11-21 12:41 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249903
|
4.8 |
MEDIUM
Network
|
netgain-systems
|
enterprise_manager
|
NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions before 10.1.12.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10586
|
2024-11-21 12:41 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249904
|
7.8 |
HIGH
Local
|
asrock
|
f-stream a-tuning restart_to_uefi rgbled
|
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10712
|
2024-11-21 12:41 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249905
|
7.8 |
HIGH
Local
|
asrock
|
f-stream a-tuning restart_to_uefi rgbled
|
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to …
|
CWE-20
Improper Input Validation
|
CVE-2018-10711
|
2024-11-21 12:41 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249906
|
7.1 |
HIGH
Local
|
asrock
|
f-stream a-tuning restart_to_uefi rgbled
|
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10710
|
2024-11-21 12:41 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249907
|
7.8 |
HIGH
Local
|
asrock
|
f-stream a-tuning restart_to_uefi rgbled
|
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10709
|
2024-11-21 12:41 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249908
|
8.8 |
HIGH
Adjacent
|
ee
|
4gee_firmware
|
An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discovered to be stored within the "core_app" binary utilised by the EE router for netw…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10532
|
2024-11-21 12:41 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249909
|
8.8 |
HIGH
Network
|
we-con
|
levistudiou
|
An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files.
|
CWE-611
XXE
|
CVE-2018-10614
|
2024-11-21 12:41 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249910
|
8.8 |
HIGH
Network
|
we-con
|
levistudiou
|
An out-of-bounds vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project files.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10610
|
2024-11-21 12:41 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|