Show filters
232 Total Results
Displaying 91-100 of 232
Sort by:
Attacker Value
Unknown
CVE-2022-28450
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
0
Attacker Value
Unknown
CVE-2022-28449
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
0
Attacker Value
Unknown
CVE-2022-28448
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
0
Attacker Value
Unknown
CVE-2021-32994
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.
0
Attacker Value
Unknown
CVE-2021-42577
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2021-42262
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
0
Attacker Value
Unknown
CVE-2022-23402
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00
0
Attacker Value
Unknown
CVE-2022-23401
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.
0
Attacker Value
Unknown
CVE-2022-22729
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.
0
Attacker Value
Unknown
CVE-2022-22151
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.
0