Show filters
941 Total Results
Displaying 41-50 of 941
Sort by:
Attacker Value
Unknown
CVE-2024-8935
Disclosure Date: November 13, 2024 (last updated February 27, 2025)
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
0
Attacker Value
Unknown
CVE-2024-10575
Disclosure Date: November 13, 2024 (last updated February 27, 2025)
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on
the network and potentially impacting connected devices.
0
Attacker Value
Unknown
CVE-2024-8933
Disclosure Date: November 13, 2024 (last updated February 27, 2025)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of
confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the
logical network while a valid user uploads or downloads a project file into the controller.
0
Attacker Value
Unknown
CVE-2024-9896
Disclosure Date: November 02, 2024 (last updated February 27, 2025)
The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-38721
Disclosure Date: November 01, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.5.0.
0
Attacker Value
Unknown
CVE-2024-49682
Disclosure Date: October 24, 2024 (last updated February 26, 2025)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership allows Phishing.This issue affects Simple Membership: from n/a through 4.5.3.
0
Attacker Value
Unknown
CVE-2024-8070
Disclosure Date: October 13, 2024 (last updated February 26, 2025)
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test
credentials in the firmware binary
0
Attacker Value
Unknown
CVE-2024-47354
Disclosure Date: October 10, 2024 (last updated February 26, 2025)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership After Login Redirection.This issue affects Simple Membership After Login Redirection: from n/a through 1.6.
0
Attacker Value
Unknown
CVE-2024-9005
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
0
Attacker Value
Unknown
CVE-2024-8884
Disclosure Date: October 08, 2024 (last updated February 26, 2025)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that
could cause exposure of credentials when attacker has access to application on network over
http
0