21
|
4.9 |
MEDIUM
Network
|
wago
|
750-331_firmware 750-8202_firmware 750-8202\/000-011_firmware 750-8202\/000-012_firmware 750-8202\/000-022_firmware 750-8202\/025-000_firmware 750-8202\/025-001_firmware 750-8202…
|
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
Update
|
-
|
CVE-2023-1619
|
2024-10-2 15:15 |
2023-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
22
|
7.5 |
HIGH
Network
wago
|
750-363\/040-000_firmware 750-362\/040-000_firmware 750-362\/000-001_firmware 750-891_firmware 750-365\/040-010_firmware 750-364\/040-010_firmware 750-362_firmware 750-363_firmwa…
|
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
Update
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2023-1150
|
2024-10-2 15:15 |
2023-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
23
|
5.3 |
MEDIUM
Network
phoenixcontact
|
fl_mguard_2102_firmware fl_mguard_4102_pci_firmware fl_mguard_4102_pcie_firmware fl_mguard_4302_firmware fl_mguard_centerport_firmware fl_mguard_centerport_vpn-1000_firmware fl_mgua…
|
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the …
Update
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2023-2673
|
2024-10-2 15:15 |
2023-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
24
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7855
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
25
|
- |
|
-
|
-
|
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
New
|
-
|
CVE-2024-45186
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
26
|
- |
|
-
|
-
|
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
New
|
-
|
CVE-2024-33662
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
27
|
- |
|
-
|
-
|
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the …
New
|
-
|
CVE-2024-21530
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
28
|
- |
|
-
|
-
|
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, …
Update
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2024-3727
|
2024-10-2 08:15 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
29
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor5
|
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vu…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-45613
|
2024-10-2 07:15 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
30
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9411
|
2024-10-2 06:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|