Show filters
75 Total Results
Displaying 1-10 of 75
Sort by:
Attacker Value
Unknown

CVE-2024-40395

Disclosure Date: August 27, 2024 (last updated August 31, 2024)
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.
Attacker Value
Unknown

CVE-2018-20092

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.
1
Attacker Value
Unknown

CVE-2018-17218

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.
Attacker Value
Unknown

CVE-2018-17217

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.
1
Attacker Value
Unknown

CVE-2018-17216

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.
1
Attacker Value
Unknown

CVE-2024-8942

Disclosure Date: September 25, 2024 (last updated October 01, 2024)
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
Attacker Value
Unknown

CVE-2024-8941

Disclosure Date: September 25, 2024 (last updated October 01, 2024)
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.
Attacker Value
Unknown

CVE-2024-8940

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
Attacker Value
Unknown

CVE-2024-6098

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could deliver a response leading to unrestricted or unregulated resource allocation. This could cause a denial-of-service condition and crash the Kepware application. By default, these functions are turned off, yet they remain accessible for users who recognize and require their advantages.
0
Attacker Value
Unknown

CVE-2024-6071

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.
0