Show filters
941 Total Results
Displaying 51-60 of 941
Sort by:
Attacker Value
Unknown

CVE-2024-8518

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user.
0
Attacker Value
Unknown

CVE-2024-8422

Disclosure Date: October 08, 2024 (last updated February 26, 2025)
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
Attacker Value
Unknown

CVE-2024-35294

Disclosure Date: October 02, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.
Attacker Value
Unknown

CVE-2024-35293

Disclosure Date: October 02, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.
Attacker Value
Unknown

CVE-2024-8306

Disclosure Date: September 11, 2024 (last updated February 26, 2025)
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
Attacker Value
Unknown

CVE-2024-6918

Disclosure Date: August 20, 2024 (last updated February 26, 2025)
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.
0
Attacker Value
Unknown

CVE-2024-38720

Disclosure Date: July 20, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EazyDocs eazydocs allows Stored XSS.This issue affects EazyDocs: from n/a through 2.5.0.
0
Attacker Value
Unknown

CVE-2024-6746

Disclosure Date: July 15, 2024 (last updated February 26, 2025)
A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file \EasySpider\resources\app\server.js of the component HTTP GET Request Handler. The manipulation with the input /../../../../../../../../../Windows/win.ini leads to path traversal: '../filedir'. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier VDB-271477 was assigned to this vulnerability. NOTE: The code maintainer explains, that this is not a big issue "because the default is that the software runs locally without going through the Internet".
Attacker Value
Unknown

CVE-2024-6407

Disclosure Date: July 11, 2024 (last updated February 26, 2025)
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.
Attacker Value
Unknown

CVE-2024-6528

Disclosure Date: July 11, 2024 (last updated February 26, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.