Show filters
991 Total Results
Displaying 151-160 of 991
Sort by:
Attacker Value
Unknown

CVE-2023-2884

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
Attacker Value
Unknown

CVE-2023-2883

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
Attacker Value
Unknown

CVE-2023-2882

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
Attacker Value
Unknown

CVE-2022-45076

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WebMat Flexible Elementor Panel plugin <= 2.3.8 versions.
Attacker Value
Unknown

CVE-2022-47393

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
Attacker Value
Unknown

CVE-2022-47392

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
Attacker Value
Unknown

CVE-2022-47391

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
Attacker Value
Unknown

CVE-2022-47390

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Attacker Value
Unknown

CVE-2022-47389

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Attacker Value
Unknown

CVE-2022-47388

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.