Show filters
818 Total Results
Displaying 211-220 of 818
Sort by:
Attacker Value
Unknown
CVE-2022-46670
Disclosure Date: December 16, 2022 (last updated February 24, 2025)
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.
0
Attacker Value
Unknown
CVE-2022-3166
Disclosure Date: December 16, 2022 (last updated February 24, 2025)
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device
0
Attacker Value
Unknown
CVE-2022-37018
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.
0
Attacker Value
Unknown
CVE-2021-3661
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
0
Attacker Value
Unknown
CVE-2022-0698
Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
0
Attacker Value
Unknown
CVE-2022-33012
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
0
Attacker Value
Unknown
CVE-2022-3388
Disclosure Date: November 21, 2022 (last updated February 24, 2025)
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA
Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
0
Attacker Value
Unknown
CVE-2022-24942
Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.
0
Attacker Value
Unknown
CVE-2022-42901
Disclosure Date: October 13, 2022 (last updated February 24, 2025)
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMT files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
0
Attacker Value
Unknown
CVE-2022-42900
Disclosure Date: October 13, 2022 (last updated February 24, 2025)
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read issues when opening crafted FBX files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
0