Show filters
941 Total Results
Displaying 251-260 of 941
Sort by:
Attacker Value
Unknown

CVE-2022-30234

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Attacker Value
Unknown

CVE-2022-30233

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is tricked into performing certain actions on a webpage. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Attacker Value
Unknown

CVE-2022-1153

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in various place, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2022-26507

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2022-0221

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)
Attacker Value
Unknown

CVE-2021-22797

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)
Attacker Value
Unknown

CVE-2021-22795

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
Attacker Value
Unknown

CVE-2021-22794

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
Attacker Value
Unknown

CVE-2019-6834

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)
Attacker Value
Unknown

CVE-2022-27847

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import templates.