Show filters
252 Total Results
Displaying 141-150 of 252
Sort by:
Attacker Value
Unknown
CVE-2021-27187
Disclosure Date: February 12, 2021 (last updated February 22, 2025)
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.
0
Attacker Value
Unknown
CVE-2020-28221
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
0
Attacker Value
Unknown
CVE-2020-12523
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
0
Attacker Value
Unknown
CVE-2020-35338
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
0
Attacker Value
Unknown
CVE-2020-29259
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.
0
Attacker Value
Unknown
CVE-2020-29258
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.
0
Attacker Value
Unknown
CVE-2020-29257
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.
0
Attacker Value
Unknown
CVE-2020-23727
Disclosure Date: December 03, 2020 (last updated November 28, 2024)
There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attacker can cause a computer crash (BSOD).
0
Attacker Value
Unknown
CVE-2020-7544
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
0
Attacker Value
Unknown
CVE-2020-14930
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.
0