Show filters
941 Total Results
Displaying 211-220 of 941
Sort by:
Attacker Value
Unknown

CVE-2022-34762

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
Attacker Value
Unknown

CVE-2022-34756

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)
Attacker Value
Unknown

CVE-2022-34759

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
Attacker Value
Unknown

CVE-2022-34754

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (V2.12.0 and prior)
Attacker Value
Unknown

CVE-2022-2329

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
Attacker Value
Unknown

CVE-2022-24324

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
Attacker Value
Unknown

CVE-2022-31504

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-32530

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option or the wrong control request when a mobile device has been compromised by a malicious application. Affected Product: Geo SCADA Mobile (Build 222 and prior)
Attacker Value
Unknown

CVE-2022-1915

Disclosure Date: June 20, 2022 (last updated February 23, 2025)
The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite)
Attacker Value
Unknown

CVE-2022-32518

Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Expert (Versions prior to V7.9.0)