Lucene search

K

Basic Security Vulnerabilities

cve
cve

CVE-2024-30534

Missing Authorization vulnerability in typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through...

6.5CVSS

6.5AI Score

0.0004EPSS

2024-06-09 09:15 AM
35
cve
cve

CVE-2024-32850

Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker.....

7.4AI Score

0.0004EPSS

2024-05-31 02:15 AM
28
cve
cve

CVE-2024-20326

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement...

7.8CVSS

6.9AI Score

0.0004EPSS

2024-05-16 02:15 PM
38
cve
cve

CVE-2024-20389

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement...

7.8CVSS

6.9AI Score

0.0004EPSS

2024-05-16 02:15 PM
39
cve
cve

CVE-2024-4144

The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of...

6.5CVSS

9.6AI Score

0.001EPSS

2024-05-14 04:17 PM
25
cve
cve

CVE-2024-4150

The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

6.1CVSS

8.4AI Score

0.001EPSS

2024-05-14 03:42 PM
29
cve
cve

CVE-2024-32947

Cross-Site Request Forgery (CSRF) vulnerability in AlumniOnline Web Services LLC WP ADA Compliance Check Basic.This issue affects WP ADA Compliance Check Basic: from n/a through...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-04-24 03:15 PM
33
cve
cve

CVE-2024-31942

Cross-Site Request Forgery (CSRF) vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through...

4.3CVSS

6.8AI Score

0.0004EPSS

2024-04-15 09:15 AM
26
cve
cve

CVE-2024-27993

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through...

7.1CVSS

9.3AI Score

0.0004EPSS

2024-03-21 03:16 PM
29
cve
cve

CVE-2024-24935

Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through...

4.3CVSS

5.6AI Score

0.0004EPSS

2024-02-12 09:15 AM
19
cve
cve

CVE-2023-46143

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a...

7.5CVSS

7.7AI Score

0.001EPSS

2023-12-14 02:15 PM
14
cve
cve

CVE-2023-46141

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected...

9.8CVSS

9.6AI Score

0.002EPSS

2023-12-14 02:15 PM
13
cve
cve

CVE-2023-40655

A reflected XSS vulnerability was discovered in the Proforms Basic component for...

6.1CVSS

6AI Score

0.0005EPSS

2023-12-14 09:15 AM
14
cve
cve

CVE-2023-47223

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0...

4.8CVSS

4.9AI Score

0.0004EPSS

2023-11-08 07:15 PM
15
cve
cve

CVE-2023-41950

Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1...

8.8CVSS

8.8AI Score

0.001EPSS

2023-10-06 03:15 PM
22
cve
cve

CVE-2023-34476

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL...

9.8CVSS

9.6AI Score

0.001EPSS

2023-08-07 05:15 PM
18
cve
cve

CVE-2022-47139

Cross-Site Request Forgery (CSRF) vulnerability in Damir Calusic WP Basic Elements plugin <= 5.2.15...

8.8CVSS

8.8AI Score

0.001EPSS

2023-05-25 09:15 AM
18
cve
cve

CVE-2023-23709

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Denis WPJAM Basic plugin <= 6.2.1...

6.5CVSS

5.5AI Score

0.0005EPSS

2023-05-16 10:15 AM
14
cve
cve

CVE-2023-25184

Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC....

7.5CVSS

7.7AI Score

0.004EPSS

2023-05-10 06:15 AM
17
cve
cve

CVE-2023-23901

Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdrop on or alter the communication sent to the WebUI of the...

6.5CVSS

6.5AI Score

0.002EPSS

2023-05-10 06:15 AM
19
cve
cve

CVE-2023-22441

Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and...

8.6CVSS

8.5AI Score

0.007EPSS

2023-05-10 06:15 AM
26
cve
cve

CVE-2021-26644

SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is...

9.8CVSS

9.6AI Score

0.003EPSS

2023-01-20 05:15 PM
21
cve
cve

CVE-2012-10004

A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file basic_cart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the attack remotely....

6.1CVSS

6AI Score

0.001EPSS

2023-01-11 07:15 AM
17
cve
cve

CVE-2022-43514

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations...

9.8CVSS

8.1AI Score

0.014EPSS

2023-01-10 12:15 PM
65
cve
cve

CVE-2022-43513

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without...

8.2CVSS

8.4AI Score

0.002EPSS

2023-01-10 12:15 PM
80
cve
cve

CVE-2022-4226

The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

4.7AI Score

0.001EPSS

2022-12-26 01:15 PM
38
cve
cve

CVE-2022-40227

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Upd...

7.5CVSS

7.4AI Score

0.002EPSS

2022-10-11 11:15 AM
32
5
cve
cve

CVE-2009-4839

Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/base_roleadmin.php, (2) admin/base_useradmin.php, (3)...

5.9AI Score

0.002EPSS

2022-10-03 04:24 PM
23
cve
cve

CVE-2009-4838

SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters. NOTE: some of these details are obtained from third party...

8.6AI Score

0.002EPSS

2022-10-03 04:24 PM
30
cve
cve

CVE-2009-4837

Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[1] parameter to base/base_qry_main.php, or the time[0][1] parameter to (2) base/base_stat_alerts.php or (3).....

5.8AI Score

0.002EPSS

2022-10-03 04:24 PM
27
cve
cve

CVE-2010-0695

Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id...

5.9AI Score

0.002EPSS

2022-10-03 04:21 PM
18
cve
cve

CVE-2010-2255

SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to...

8.7AI Score

0.002EPSS

2022-10-03 04:21 PM
32
cve
cve

CVE-2010-4305

Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies.....

6.5AI Score

0.001EPSS

2022-10-03 04:21 PM
48
cve
cve

CVE-2010-4304

The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU)...

6.8AI Score

0.001EPSS

2022-10-03 04:21 PM
18
cve
cve

CVE-2012-5569

Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email...

5.8AI Score

0.001EPSS

2022-10-03 04:15 PM
17
2
cve
cve

CVE-2008-2429

Multiple SQL injection vulnerabilities in Calendarix Basic 0.8.20071118 allow remote attackers to execute arbitrary SQL commands via (1) the catsearch parameter to cal_search.php or (2) the catview parameter to cal_cat.php. NOTE: vector 1 might overlap CVE-2007-3183.3, and vector 2 might overlap...

8.2AI Score

0.016EPSS

2022-10-03 04:14 PM
27
cve
cve

CVE-2022-31800

An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the...

9.8CVSS

9.6AI Score

0.007EPSS

2022-06-21 08:15 AM
47
3
cve
cve

CVE-2022-33175

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in...

9.8CVSS

9.3AI Score

0.003EPSS

2022-06-13 06:15 PM
357
2
cve
cve

CVE-2022-33174

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an....

9.8CVSS

7.6AI Score

0.008EPSS

2022-06-13 06:15 PM
58
3
cve
cve

CVE-2022-1669

A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any...

8.1CVSS

8.1AI Score

0.001EPSS

2022-05-24 06:15 PM
41
5
cve
cve

CVE-2021-21948

A heap-based buffer overflow vulnerability exists in the readDatHeadVec functionality of AnyCubic Chitubox AnyCubic Plugin 1.0.0. A specially-crafted GF file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this...

7.8CVSS

7.7AI Score

0.001EPSS

2022-04-14 08:15 PM
51
cve
cve

CVE-2022-23449

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one ...

7.3CVSS

7.1AI Score

0.0004EPSS

2022-04-12 09:15 AM
55
cve
cve

CVE-2022-23450

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content ...

9.8CVSS

9.5AI Score

0.003EPSS

2022-04-12 09:15 AM
52
cve
cve

CVE-2022-23448

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes. This could al...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-04-12 09:15 AM
56
cve
cve

CVE-2021-45117

The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer...

6.5CVSS

6.4AI Score

0.001EPSS

2022-03-21 03:15 PM
71
4
cve
cve

CVE-2022-26320

The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization...

9.1CVSS

9.1AI Score

0.002EPSS

2022-03-14 06:15 PM
202
1
cve
cve

CVE-2021-24867

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to....

9.8CVSS

9.4AI Score

0.004EPSS

2022-02-21 11:15 AM
133
2
cve
cve

CVE-2021-22817

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix.....

7.8CVSS

7.4AI Score

0.0004EPSS

2022-02-09 11:15 PM
57
cve
cve

CVE-2021-40857

Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1...

8.8CVSS

8.7AI Score

0.014EPSS

2021-12-13 04:15 AM
43
cve
cve

CVE-2021-40858

Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd...

4.9CVSS

5.2AI Score

0.013EPSS

2021-12-13 04:15 AM
34
Total number of security vulnerabilities165