| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack. |
| LaunchServices in Apple OS X before 10.10.3 allows local users to cause a denial of service (Finder crash) via crafted localization data. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network. |
| Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file. |
| Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter. |
| Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin |
| Open Proxy in filedownload v1.4 wordpress plugin |
| Blind SQL Injection in filedownload v1.4 wordpress plugin |
| XSS in filedownload v1.4 wordpress plugin |
| Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin |
| Remote file download vulnerability in recent-backups v0.7 wordpress plugin |
| Remote file download in simple-image-manipulator v1.0 wordpress plugin |
| Blind SQL Injection in wordpress plugin dukapress v2.5.9 |
| Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin |
| Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 |
| Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request. |
| Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2 |
| Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 |