Show filters
207 Total Results
Displaying 111-120 of 207
Sort by:
Attacker Value
Unknown

CVE-2021-42706

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer
Attacker Value
Unknown

CVE-2021-43555

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution.
Attacker Value
Unknown

CVE-2021-41578

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
Attacker Value
Unknown

CVE-2021-22704

Disclosure Date: September 02, 2021 (last updated February 23, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.
Attacker Value
Unknown

CVE-2021-32931

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
An uninitialized pointer in FATEK Automation FvDesigner, Versions 1.5.88 and prior may be exploited while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-32947

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-32939

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-20779

Disclosure Date: July 07, 2021 (last updated February 22, 2025)
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Attacker Value
Unknown

CVE-2021-33000

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Attacker Value
Unknown

CVE-2021-33002

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).