| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file. |
| Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter. |
| Remote file upload vulnerability in mailcwp v1.99 wordpress plugin |
| Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin |
| Open Proxy in filedownload v1.4 wordpress plugin |
| Blind SQL Injection in filedownload v1.4 wordpress plugin |
| XSS in filedownload v1.4 wordpress plugin |
| Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin |
| Remote file download vulnerability in recent-backups v0.7 wordpress plugin |
| Remote file download vulnerability in wptf-image-gallery v1.03 |
| Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2 |
| Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 |
| Blind SQL Injection in wordpress plugin dukapress v2.5.9 |
| Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin |
| Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 |
| Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request. |
| IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. |
| IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string. |
| Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. |