Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-5964

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2023-3324

Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
Attacker Value
Unknown

CVE-2023-3323

Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
Attacker Value
Unknown

CVE-2023-3322

Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
Attacker Value
Unknown

CVE-2023-3321

Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
Attacker Value
Unknown

CVE-2022-34837

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
Attacker Value
Unknown

CVE-2022-34838

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.
Attacker Value
Unknown

CVE-2022-34836

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities such as the start and stop of various activity and the last error code etc.
Attacker Value
Unknown

CVE-2019-15638

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
Attacker Value
Unknown

CVE-2014-2345

Disclosure Date: June 05, 2014 (last updated October 05, 2023)
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow remote attackers to cause a denial of service (infinite loop and process crash) by sending a crafted DNP3 packet over TCP.
0