Show filters
941 Total Results
Displaying 21-30 of 941
Sort by:
Attacker Value
Unknown

CVE-2024-10497

Disclosure Date: January 17, 2025 (last updated February 27, 2025)
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device.
0
Attacker Value
Unknown

CVE-2024-12476

Disclosure Date: January 17, 2025 (last updated February 27, 2025)
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.
0
Attacker Value
Unknown

CVE-2024-12399

Disclosure Date: January 17, 2025 (last updated February 27, 2025)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.
0
Attacker Value
Unknown

CVE-2024-11425

Disclosure Date: January 17, 2025 (last updated February 27, 2025)
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
0
Attacker Value
Unknown

CVE-2024-11139

Disclosure Date: January 17, 2025 (last updated February 27, 2025)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to exploit these issues to potentially execute arbitrary code when opening a malicious project file.
0
Attacker Value
Unknown

CVE-2025-22826

Disclosure Date: January 09, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce, wp.insider Sell Digital Downloads allows Stored XSS.This issue affects Sell Digital Downloads: from n/a through 2.2.7.
0
Attacker Value
Unknown

CVE-2023-47648

Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.3.5.
0
Attacker Value
Unknown

CVE-2024-11999

Disclosure Date: December 17, 2024 (last updated February 27, 2025)
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
0
Attacker Value
Unknown

CVE-2024-54376

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.
0
Attacker Value
Unknown

CVE-2024-55980

Disclosure Date: December 16, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webriderz Wr Age Verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through 2.0.0.
0