Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2024-5964
Disclosure Date: July 18, 2024 (last updated January 05, 2025)
The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-3324
Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
0
Attacker Value
Unknown
CVE-2023-3323
Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
0
Attacker Value
Unknown
CVE-2023-3322
Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
0
Attacker Value
Unknown
CVE-2023-3321
Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
0
Attacker Value
Unknown
CVE-2022-34837
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
0
Attacker Value
Unknown
CVE-2022-34838
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.
0
Attacker Value
Unknown
CVE-2022-34836
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities such as the start and stop of various activity and the last error code etc.
0
Attacker Value
Unknown
CVE-2019-15638
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
0
Attacker Value
Unknown
CVE-2014-2345
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow remote attackers to cause a denial of service (infinite loop and process crash) by sending a crafted DNP3 packet over TCP.
0