Show filters
232 Total Results
Displaying 31-40 of 232
Sort by:
Attacker Value
Unknown
CVE-2023-5908
Disclosure Date: November 30, 2023 (last updated December 07, 2023)
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
0
Attacker Value
Unknown
CVE-2023-46590
Disclosure Date: November 14, 2023 (last updated December 22, 2024)
A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.
0
Attacker Value
Unknown
CVE-2023-45064
Disclosure Date: October 18, 2023 (last updated October 26, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions.
0
Attacker Value
Unknown
CVE-2023-26151
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
0
Attacker Value
Unknown
CVE-2023-26150
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication.
**Note:**
This issue is a result of missing checks for services that require an active session.
0
Attacker Value
Unknown
CVE-2023-34011
Disclosure Date: September 01, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ShopConstruct plugin <= 1.1.2 versions.
0
Attacker Value
Unknown
CVE-2023-2685
Disclosure Date: July 28, 2023 (last updated October 08, 2023)
A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry is not enclosed in quotation marks, potential attackers could possibly call up another application than the AO-OPC server by starting the service. The service might be started with system user privileges which could cause a shift in user access privileges.
It is unlikely to exploit the vulnerability in well maintained Windows installations since the attacker would need write access to system folders.
An update is available that resolves the vulnerability found during an internal review in the product AO-OPC = 3.2.1
0
Attacker Value
Unknown
CVE-2023-37200
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that
could cause loss of confidentiality when replacing a project file on the local filesystem and after
manual restart of the server.
0
Attacker Value
Unknown
CVE-2023-2161
Disclosure Date: May 16, 2023 (last updated October 08, 2023)
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that
could cause unauthorized read access to the file system when a malicious configuration file is
loaded on to the software by a local user.
0
Attacker Value
Unknown
CVE-2023-26593
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM managed may be escalated. As a result, the control system may be operated with the escalated user privilege. To exploit this vulnerability, the following prerequisites must be met: (1)An attacker has obtained user credentials where the affected product is installed, (2)CENTUM Authentication Mode is used for user authentication when CENTUM VP is used. The affected products and versions are as follows: CENTUM CS 1000, CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class) R2.01.00 to R3.09.50, CENTUM VP (Including CENTUM VP Entry Class) R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, and R6.01.00 and later, B/M9000 CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R7.04.51 and R8.01.01 and later
0