Show filters
207 Total Results
Displaying 121-130 of 207
Sort by:
Attacker Value
Unknown

CVE-2021-33004

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Attacker Value
Unknown

CVE-2021-24370

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
Attacker Value
Unknown

CVE-2021-22705

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
Attacker Value
Unknown

CVE-2020-7035

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.
Attacker Value
Unknown

CVE-2021-31410

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
Attacker Value
Unknown

CVE-2021-22681

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Attacker Value
Unknown

CVE-2021-22683

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-22666

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being processed, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-22638

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds read while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-22662

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.