Show filters
53 Total Results
Displaying 21-30 of 53
Sort by:
Attacker Value
Unknown

CVE-2023-22389

Disclosure Date: January 30, 2023 (last updated November 08, 2023)
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file.  
Attacker Value
Unknown

CVE-2023-24020

Disclosure Date: January 30, 2023 (last updated November 08, 2023)
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login.
Attacker Value
Unknown

CVE-2023-22315

Disclosure Date: January 30, 2023 (last updated November 08, 2023)
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary code.
Attacker Value
Unknown

CVE-2022-2551

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full site backup without authenticating.
Attacker Value
Unknown

CVE-2022-2552

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
Attacker Value
Unknown

CVE-2022-24237

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.
Attacker Value
Unknown

CVE-2022-24236

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.
Attacker Value
Unknown

CVE-2022-24235

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
Attacker Value
Unknown

CVE-2020-22552

Disclosure Date: October 28, 2020 (last updated February 15, 2024)
The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.
Attacker Value
Unknown

CVE-2019-20921

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.