Show filters
941 Total Results
Displaying 261-270 of 941
Sort by:
Attacker Value
Unknown

CVE-2022-27846

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create or modify slider.
Attacker Value
Unknown

CVE-2021-30066

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
Attacker Value
Unknown

CVE-2021-30065

Disclosure Date: April 03, 2022 (last updated October 07, 2023)
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.
Attacker Value
Unknown

CVE-2021-30064

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).
Attacker Value
Unknown

CVE-2021-30063

Disclosure Date: April 03, 2022 (last updated October 07, 2023)
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.
Attacker Value
Unknown

CVE-2021-30062

Disclosure Date: April 03, 2022 (last updated October 07, 2023)
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer.
Attacker Value
Unknown

CVE-2021-30061

Disclosure Date: April 03, 2022 (last updated October 07, 2023)
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, physically proximate attackers can execute code via a crafted file on a USB stick.
Attacker Value
Unknown

CVE-2022-25609

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with contributor or higher user role to inject the malicious code.
Attacker Value
Unknown

CVE-2022-25608

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action.
Attacker Value
Unknown

CVE-2020-25184

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.