Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2024-12142

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restricted web page, modification of web page and denial of service when specific web pages are modified and restricted functions are invoked.
0
Attacker Value
Unknown

CVE-2024-11425

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
0
Attacker Value
Unknown

CVE-2024-55992

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through 1.4.4.
0
Attacker Value
Unknown

CVE-2024-8938

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in memory size computation.
0
Attacker Value
Unknown

CVE-2024-8937

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in the authentication process.
0
Attacker Value
Unknown

CVE-2024-8936

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.
0
Attacker Value
Unknown

CVE-2024-8935

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
0
Attacker Value
Unknown

CVE-2024-8933

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller.
0
Attacker Value
Unknown

CVE-2024-35173

Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Missing Authorization vulnerability in PluginEver Serial Numbers for WooCommerce – License Manager.This issue affects Serial Numbers for WooCommerce – License Manager: from n/a through 1.7.3.
0
Attacker Value
Unknown

CVE-2024-1282

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0