Show filters
796 Total Results
Displaying 31-40 of 796
Sort by:
Attacker Value
Unknown
CVE-2024-8070
Disclosure Date: October 13, 2024 (last updated October 14, 2024)
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test
credentials in the firmware binary
0
Attacker Value
Unknown
CVE-2024-9005
Disclosure Date: October 08, 2024 (last updated October 08, 2024)
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
0
Attacker Value
Unknown
CVE-2024-8884
Disclosure Date: October 08, 2024 (last updated October 08, 2024)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that
could cause exposure of credentials when attacker has access to application on network over
http
0
Attacker Value
Unknown
CVE-2024-8518
Disclosure Date: October 08, 2024 (last updated October 08, 2024)
CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft
2 application when a specially crafted project file is loaded by an application user.
0
Attacker Value
Unknown
CVE-2024-8422
Disclosure Date: October 08, 2024 (last updated October 17, 2024)
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial
of service and loss of confidentiality & integrity when application user opens a malicious Zelio
Soft 2 project file.
0
Attacker Value
Unknown
CVE-2024-8306
Disclosure Date: September 11, 2024 (last updated September 19, 2024)
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity and availability of the workstation when non-admin
authenticated user tries to perform privilege escalation by tampering with the binaries.
0
Attacker Value
Unknown
CVE-2024-6918
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability
exists that could cause a crash of the Accutech Manager when receiving a specially crafted
request over port 2536/TCP.
0
Attacker Value
Unknown
CVE-2024-6407
Disclosure Date: July 11, 2024 (last updated July 13, 2024)
CWE-200: Information Exposure vulnerability exists that could cause disclosure of
credentials when a specially crafted message is sent to the device.
0
Attacker Value
Unknown
CVE-2024-6528
Disclosure Date: July 11, 2024 (last updated July 13, 2024)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site
Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting
condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a
page containing the injected payload.
0
Attacker Value
Unknown
CVE-2024-5681
Disclosure Date: July 11, 2024 (last updated July 13, 2024)
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service,
privilege escalation, and potentially kernel execution when a malicious actor with local user
access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
0