Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown
CVE-2023-43986
Disclosure Date: October 19, 2023 (last updated October 26, 2023)
DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken.
0
Attacker Value
Unknown
CVE-2023-34392
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator.
See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.
This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20.
0
Attacker Value
Unknown
CVE-2023-31175
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands with the highest level privilege on the system.
See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.
This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20.
0
Attacker Value
Unknown
CVE-2023-31174
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device operator.
See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.
This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20.
0
Attacker Value
Unknown
CVE-2023-31173
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass.
See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.
This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20.
0
Attacker Value
Unknown
CVE-2023-34175
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
0
Attacker Value
Unknown
CVE-2023-34369
Disclosure Date: July 25, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
0
Attacker Value
Unknown
CVE-2023-1893
Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.
0
Attacker Value
Unknown
CVE-2022-25164
Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.
0
Attacker Value
Unknown
CVE-2022-40976
Disclosure Date: November 24, 2022 (last updated December 22, 2024)
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
0