| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password. |
| The mach_vm_read functionality in the kernel in Apple OS X before 10.10.3 allows local users to cause a denial of service (system crash) via unspecified vectors. |
| Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. |
| Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file. |
| Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter. |
| Remote file upload vulnerability in mailcwp v1.99 wordpress plugin |
| Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin |
| Open Proxy in filedownload v1.4 wordpress plugin |
| Blind SQL Injection in filedownload v1.4 wordpress plugin |
| XSS in filedownload v1.4 wordpress plugin |
| Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin |
| Remote file download vulnerability in recent-backups v0.7 wordpress plugin |
| Remote file download vulnerability in wptf-image-gallery v1.03 |
| Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2 |
| Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 |
| Remote file download in simple-image-manipulator v1.0 wordpress plugin |
| Blind SQL Injection in wordpress plugin dukapress v2.5.9 |
| Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin |