Show filters
941 Total Results
Displaying 1-10 of 941
Sort by:
Attacker Value
High

CVE-2019-5021

Disclosure Date: May 08, 2019 (last updated November 27, 2024)
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Attacker Value
High

CVE-2021-22707

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
Attacker Value
Very High

CVE-2021-22779

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.
Attacker Value
Unknown

CVE-2025-26763

Disclosure Date: February 22, 2025 (last updated February 23, 2025)
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.
0
Attacker Value
Unknown

CVE-2025-0816

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the device.
0
Attacker Value
Unknown

CVE-2025-0815

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.
0
Attacker Value
Unknown

CVE-2025-0814

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality of the breaker remains intact during the attack.
0
Attacker Value
Unknown

CVE-2025-0327

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.
0
Attacker Value
Unknown

CVE-2025-1070

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.
0
Attacker Value
Unknown

CVE-2025-1060

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
0