High · CVSS 8.1
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.
Published Apr 29, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.
Published Apr 1, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.
Published Apr 1, 2022 · Updated Apr 16, 2025
Critical · CVSS 10
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.
Published Apr 1, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.
Published Apr 1, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 8.2
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Published Apr 1, 2022 · Updated Apr 16, 2025
Low · CVSS 3.7
Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Published Apr 1, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.
Published Apr 4, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is already active.
Published Apr 4, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.
Published Apr 4, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC and read the project without authorization.
Published Apr 4, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.
Published Apr 4, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.
Published Apr 4, 2022 · Updated Apr 16, 2025
High · CVSS 7.5
Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.
Published Apr 4, 2022 · Updated Apr 16, 2025
Medium · CVSS 6.1
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.
Published Apr 20, 2022 · Updated Apr 16, 2025
Medium · CVSS 6
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.
Published Apr 20, 2022 · Updated Apr 16, 2025
Medium · CVSS 6
The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the binary and modify files to gain privilege escalation.
Published Apr 20, 2022 · Updated Apr 16, 2025
Medium · CVSS 6.1
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.
Published Apr 20, 2022 · Updated Apr 16, 2025
Medium · CVSS 6.1
The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized access rights.
Published Apr 20, 2022 · Updated Apr 16, 2025
Medium · CVSS 4.3
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.
Published Apr 22, 2022 · Updated Apr 16, 2025
High · CVSS 7.1
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.
Published Apr 22, 2022 · Updated Apr 16, 2025
Medium · CVSS 4.9
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
Published Apr 28, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.8
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.
Published Apr 28, 2022 · Updated Apr 16, 2025
High · CVSS 7.6
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Published Apr 29, 2022 · Updated Apr 16, 2025
Critical · CVSS 9.1
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.
Published Apr 15, 2025 · Updated Apr 16, 2025
Critical · CVSS 9.8
A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
An out-of-bounds write vulnerability exists in the TIFF YCbCr image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer oveflow takes place trying to copy the first 12 bits from local variable.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer oveflow takes place trying to copy the second 12 bits from local variable.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer overflow takes place when the `SOF3` precision is lower than 9.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer overflow takes place when the `SOF3` precision is greater or equal than 9.
Published Apr 14, 2022 · Updated Apr 15, 2025
High · CVSS 7.8
A heap-based buffer overflow vulnerability exists in the readDatHeadVec functionality of AnyCubic Chitubox AnyCubic Plugin 1.0.0. A specially-crafted GF file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.8
An improper array index validation vulnerability exists in the JPEG-JFIF Scan header parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to an out-of-bounds write and potential code exectuion. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
High · CVSS 8.2
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Medium · CVSS 6.5
An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 10
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Medium · CVSS 5.3
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
High · CVSS 8.1
An out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025
Critical · CVSS 9.3
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
Published Apr 14, 2022 · Updated Apr 15, 2025