Show filters
941 Total Results
Displaying 201-210 of 941
Sort by:
Attacker Value
Unknown
CVE-2022-33943
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
Authenticated (contributor or higher user role) Cross-Site Scripting (XSS) vulnerability in Nico Amarilla's BxSlider WP plugin <= 2.0.0 at WordPress.
0
Attacker Value
Unknown
CVE-2022-31904
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.
0
Attacker Value
Unknown
CVE-2022-34764
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service when parsing the URL. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
0
Attacker Value
Unknown
CVE-2022-34761
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
0
Attacker Value
Unknown
CVE-2022-34763
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improper verification of the firmware signature. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
0
Attacker Value
Unknown
CVE-2022-34758
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. Affected Products: Easergy P5 (V01.401.102 and prior)
0
Attacker Value
Unknown
CVE-2022-34753
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)
0
Attacker Value
Unknown
CVE-2022-34760
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
0
Attacker Value
Unknown
CVE-2022-34765
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
0
Attacker Value
Unknown
CVE-2022-34757
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between Easergy Pro software and the device, which may allow an attacker to observe protected communication details. Affected Products: Easergy P5 (V01.401.102 and prior)
0