961
|
- |
|
-
|
-
|
The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information and upload files with…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2025-24865
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
962
|
- |
|
-
|
-
|
An attacker may inject commands via specially-crafted post requests.
|
CWE-77
Command Injection
|
CVE-2025-24861
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
963
|
- |
|
-
|
-
|
With a specially crafted Python script, an attacker could send
continuous startMeasurement commands over an unencrypted Bluetooth
connection to the affected device. This would prevent the device fr…
|
CWE-248
Uncaught Exception
|
CVE-2025-24836
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
964
|
- |
|
-
|
-
|
An attacker could obtain firmware files and reverse engineer their
intended use leading to loss of confidentiality and integrity of the
hardware devices enabled by the Qardio iOS and Android applic…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2025-23421
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
965
|
- |
|
-
|
-
|
mySCADA myPRO Manager
is vulnerable to cross-site request forgery (CSRF), which could allow
an attacker to obtain sensitive information. An attacker would need to
trick the victim in to visiting a…
|
CWE-352
Origin Validation Error
|
CVE-2025-23411
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
966
|
- |
|
-
|
-
|
mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2025-22896
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
967
|
- |
|
-
|
-
|
The Qardio Arm iOS application exposes sensitive data such as usernames
and passwords in a plist file. This allows an attacker to log in to
production-level development accounts and access an engin…
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2025-20615
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
968
|
- |
|
-
|
-
|
The Dingtian DT-R0 Series is vulnerable to an exploit that allows
attackers to bypass login requirements by directly navigating to the
main page.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-1283
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
969
|
- |
|
-
|
-
|
Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially lead…
|
-
|
CVE-2024-57378
|
2025-02-14 07:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
970
|
- |
|
-
|
-
|
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks.
Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests,
a valid HTTP request can also be sent to Kvrocks as a …
|
-
|
CVE-2025-25069
|
2025-02-14 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|