Show filters
941 Total Results
Displaying 91-100 of 941
Sort by:
Attacker Value
Unknown

CVE-2024-2051

Disclosure Date: March 18, 2024 (last updated February 26, 2025)
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.
0
Attacker Value
Unknown

CVE-2024-2050

Disclosure Date: March 18, 2024 (last updated February 26, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the context of the product.
0
Attacker Value
Unknown

CVE-2023-6409

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
Attacker Value
Unknown

CVE-2023-6408

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
Attacker Value
Unknown

CVE-2023-27975

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
Attacker Value
Unknown

CVE-2024-0248

Disclosure Date: February 12, 2024 (last updated October 10, 2024)
The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.
Attacker Value
Unknown

CVE-2023-6029

Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
Attacker Value
Unknown

CVE-2023-7032

Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
Attacker Value
Unknown

CVE-2023-33209

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through 1.2.
Attacker Value
Unknown

CVE-2023-47506

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Master slider Master Slider Pro allows SQL Injection.This issue affects Master Slider Pro: from n/a through 3.6.5.