9.3

CVSS4.0

CVE-2025-25067 - mySCADA myPRO Manager OS Command Injection

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

๐Ÿ“… Published: Feb. 13, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: April 23, 2025, 6:45 p.m.

5.1

CVSS4.0

CVE-2025-23411 - mySCADA myPRO Manager Cross-Site Request Forgery

mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.

๐Ÿ“… Published: Feb. 13, 2025, 9:33 p.m. ๐Ÿ”„ Last Modified: March 4, 2025, 8:59 p.m.

9.2

CVSS4.0

CVE-2025-22896 - mySCADA myPRO Manager Cleartext Storage of Sensitive Information

mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

๐Ÿ“… Published: Feb. 13, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: March 4, 2025, 8:59 p.m.

10

CVSS4.0

CVE-2025-24865 - mySCADA myPRO Manager Missing Authentication for Critical Function

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

๐Ÿ“… Published: Feb. 13, 2025, 9:29 p.m. ๐Ÿ”„ Last Modified: March 4, 2025, 8:59 p.m.

8.7

CVSS4.0

CVE-2025-24861 - Outback Power Mojave Inverter Command Injection

An attacker may inject commands via specially-crafted post requests.

๐Ÿ“… Published: Feb. 13, 2025, 9:20 p.m. ๐Ÿ”„ Last Modified: March 4, 2025, 7:24 p.m.

8.7

CVSS4.0

CVE-2025-25281 - Outback Power Mojave Inverter Exposure of Sensitive Information to an Unauthorized Actor

An attacker may modify the URL to discover sensitive information about the target network.

๐Ÿ“… Published: Feb. 13, 2025, 9:18 p.m. ๐Ÿ”„ Last Modified: April 10, 2025, 7:40 p.m.

8.7

CVSS4.0

CVE-2025-26473 - Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings

The Mojave Inverter uses the GET method for sensitive information.

๐Ÿ“… Published: Feb. 13, 2025, 9:17 p.m. ๐Ÿ”„ Last Modified: March 19, 2025, 10:34 a.m.

9.3

CVSS4.0

CVE-2025-1283 - Dingtian DT-R0 Series Authentication Bypass Using an Alternate Path or Channel

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

๐Ÿ“… Published: Feb. 13, 2025, 9:11 p.m. ๐Ÿ”„ Last Modified: April 10, 2025, 6:55 p.m.

7.3

CVSS3.1

CVE-2024-11347 - Access of Resource Using Incompatible Type in Postscript interpreter

Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

๐Ÿ“… Published: Feb. 13, 2025, 6:55 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 7:15 p.m.

7.3

CVSS3.1

CVE-2024-11346 - Access of Resource Using Incompatible Type in Postscript interpreter

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001โ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 6:54 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 7:17 p.m.
Total resulsts: 343740
Page 6193 of 34,374
ยซ previous page ยป next page
Filters