Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown
CVE-2024-12142
Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could
cause information disclosure of restricted web page, modification of web page and denial of
service when specific web pages are modified and restricted functions are invoked.
0
Attacker Value
Unknown
CVE-2024-11425
Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the
product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
0
Attacker Value
Unknown
CVE-2024-55992
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through 1.4.4.
0
Attacker Value
Unknown
CVE-2024-8938
Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a
crafted Modbus function call to tamper with memory area involved in memory size computation.
0
Attacker Value
Unknown
CVE-2024-8937
Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code execution after a successful Man-In-The Middle attack followed by sending a
crafted Modbus function call to tamper with memory area involved in the authentication process.
0
Attacker Value
Unknown
CVE-2024-8936
Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory
after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper
with memory.
0
Attacker Value
Unknown
CVE-2024-8935
Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
0
Attacker Value
Unknown
CVE-2024-8933
Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of
confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the
logical network while a valid user uploads or downloads a project file into the controller.
0
Attacker Value
Unknown
CVE-2024-35173
Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Missing Authorization vulnerability in PluginEver Serial Numbers for WooCommerce – License Manager.This issue affects Serial Numbers for WooCommerce – License Manager: from n/a through 1.7.3.
0
Attacker Value
Unknown
CVE-2024-1282
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0