Threat Encyclopedia

    ICS Schneider Electric Pelco DS-NVs Rvctl.RVControl.1 Buffer Overflow -1 (CVE-2015-0982)

    A buffer overflow vulnerability exists in Schneider Electric Pelco DS-NV Software package.

    Updated At: 2025/06/27


    ICS Schneider Electric Pelco DS-NVs Rvctl.RVControl.1 Buffer Overflow -2 (CVE-2015-0982)

    A buffer overflow vulnerability exists in Schneider Electric Pelco DS-NV Software package.

    Updated At: 2025/06/27


    ICS Franklin Fueling Systems TS-550 EVO Information Disclosure (CVE-2013-7247)

    Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user names and password hashes) via crafted HTTP POST request.

    Updated At: 2025/06/26


    ICS SolarView Compact version 6.0 Directory Traversal (CVE-2022-29298)

    SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

    Updated At: 2025/06/26


    WEB PlaySMS index.php Unauthenticated Template Injection Code Execution (CVE-2020-8644)

    There is a preauth Server-Side Template Injection vulnerability that leads to remote code execution in PlaySMS before version 1.4.3.

    Updated At: 2025/06/26


    SSH Ericsson Erlang OTP SSH Server Remote Code Execution (CVE-2025-32433) state 1-F/Flow

    A remote code execution vulnerability exists in Ericsson Erlang OTP SSH Server. The vulnerability is due to execution of critical functions prior to authentication completion. A remote, unauthenticated attacker could exploit this vulnerability by sending crafted packets to the target server. Successful exploitation could result in arbitrary code execution under the context of the vulnerable application.

    Updated At: 2025/06/25


    SSH Ericsson Erlang OTP SSH Server Remote Code Execution (CVE-2025-32433) state 0

    A remote code execution vulnerability exists in Ericsson Erlang OTP SSH Server. The vulnerability is due to execution of critical functions prior to authentication completion. A remote, unauthenticated attacker could exploit this vulnerability by sending crafted packets to the target server. Successful exploitation could result in arbitrary code execution under the context of the vulnerable application.

    Updated At: 2025/06/25


    WEB LinuxKI Toolset 6.01 Remote Command Execution (CVE-2020-7209)

    There is a vulnerability in LinuxKI Toolset <= 6.01 which allows remote code execution. The kivis.php pid parameter received from the user is sent to the shell_exec function, resulting in security vulnerability.

    Updated At: 2025/06/25


    WEB SAP NetWeaver AS JAVA unauthenticated WebService User Creation (CVE-2020-6287)

    SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user.

    Updated At: 2025/06/25


    WEB MailEnable Cross Site Scripting vulnerability (CVE-2025-44148)

    Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component.

    Updated At: 2025/06/25


    WEB Infoblox NETMRI via skipjackUsername Unauthenticated SQL Injection (CVE-2025-32814)

    An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

    Updated At: 2025/06/25


    ICS Rockwell Automation ThinManager ThinServer Path Traversal File Deletion (CVE-2023-2915)

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition.

    Updated At: 2025/06/25


    WEB Asus GT-AC2900 Authentication Bypass (CVE-2021-32030)

    The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.

    Updated At: 2025/06/25


    WEB Adobe ColdFusion DataSourceDef Security Feature Bypass (CVE-2025-43560)

    A security feature bypass vulnerability has been reported in Adobe ColdFusion. The vulnerability is due to insufficient validation of user data when creating data sources on the target server.

    Updated At: 2025/06/25


    ICS Rockwell Automation PowerMonitor 1000 Authentication Bypass (CVE-2024-12371)

    A device takeover vulnerability exists in the affected product. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.

    Updated At: 2025/06/25


    MALWARE-FILE-TRANSFER TROJ_GEN.R002C0DC525-2110292

    TROJ_GEN.R002C0DC525

    Updated At: 2025/06/25


    ICS SolarView Compact version 6.0 Cross-Site Scripting -1 (CVE-2021-20660)

    Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.

    Updated At: 2025/06/25


    ICS Schneider Electric spaceLYnk and Wiser for KNX Brute Force (CVE-2020-7525)

    Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.

    Updated At: 2025/06/24


    WEB Cacti Group Cacti remote_agent.php Command Injection (CVE-2022-46169)

    A command injection and IP restriction bypass vulnerability has been reported in Cacti. The vulnerability is due to an access control weakness and insufficient validation of user data when receiving requests from Cacti pollers. A remote, unauthenticated attacker could exploit this vulnerability by sending a crafted request to the target server. Successful exploitation could lead to arbitrary command execution in the security context of the web server running the application.

    Updated At: 2025/06/24


    WEB Sophos Firewall User Portal and Webadmin Authentication Bypass -1 (CVE-2022-1040)

    An authentication bypass vulnerability has been reported for Sophos Firewall. This vulnerability is due to insufficient sanitization of null characters in the "json" parameter sent to the Controller endpoint.

    Updated At: 2025/06/24


This website uses cookies to ensure you get the best experience on our website.

Learn more