Show filters
147 Total Results
Displaying 11-20 of 147
Sort by:
Attacker Value
Unknown

CVE-2024-8609

Disclosure Date: September 27, 2024 (last updated October 05, 2024)
Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information.This issue affects ValeApp: before v2.0.0.
Attacker Value
Unknown

CVE-2024-8608

Disclosure Date: September 27, 2024 (last updated October 05, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS.This issue affects ValeApp: before v2.0.0.
Attacker Value
Unknown

CVE-2024-8607

Disclosure Date: September 27, 2024 (last updated October 05, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.This issue affects ValeApp: before v2.0.0.
Attacker Value
Unknown

CVE-2023-35065

Disclosure Date: September 05, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection.This issue affects Paint Production Management: before 2.1.
Attacker Value
Unknown

CVE-2023-25428

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.
Attacker Value
Unknown

CVE-2022-27893

Disclosure Date: November 04, 2022 (last updated December 22, 2024)
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.
Attacker Value
Unknown

CVE-2022-29824

Disclosure Date: May 03, 2022 (last updated November 08, 2023)
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Attacker Value
Unknown

CVE-2020-23620

Disclosure Date: May 02, 2022 (last updated October 07, 2023)
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
Attacker Value
Unknown

CVE-2020-25167

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with insufficient privileges for an AF attribute.
Attacker Value
Unknown

CVE-2020-25163

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.