Show filters
941 Total Results
Displaying 131-140 of 941
Sort by:
Attacker Value
Unknown

CVE-2023-2569

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Attacker Value
Unknown

CVE-2023-1049

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
Attacker Value
Unknown

CVE-2022-46680

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.
Attacker Value
Unknown

CVE-2023-2161

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user. 
Attacker Value
Unknown

CVE-2023-25797

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 versions.
Attacker Value
Unknown

CVE-2023-25620

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
Attacker Value
Unknown

CVE-2023-25619

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
Attacker Value
Unknown

CVE-2023-29410

Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
Attacker Value
Unknown

CVE-2023-28004

Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution.
Attacker Value
Unknown

CVE-2023-29413

Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.