Show filters
188 Total Results
Displaying 31-40 of 188
Sort by:
Attacker Value
Unknown

CVE-2024-21914

Disclosure Date: March 25, 2024 (last updated April 02, 2024)
A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.
0
Attacker Value
Unknown

CVE-2024-2247

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
0
Attacker Value
Unknown

CVE-2023-42661

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
0
Attacker Value
Unknown

CVE-2023-42509

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
0
Attacker Value
Unknown

CVE-2023-42662

Disclosure Date: March 07, 2024 (last updated March 07, 2024)
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
0
Attacker Value
Unknown

CVE-2024-21915

Disclosure Date: February 16, 2024 (last updated December 21, 2024)
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.
Attacker Value
Unknown

CVE-2024-21917

Disclosure Date: January 31, 2024 (last updated February 08, 2024)
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.  If exploited, a malicious user could potentially retrieve user information and modify settings without any authentication.
Attacker Value
Unknown

CVE-2023-6077

Disclosure Date: December 18, 2023 (last updated December 22, 2023)
The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected
Attacker Value
Unknown

CVE-2023-46290

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.
Attacker Value
Unknown

CVE-2023-46289

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.