CVE-2022-2302

Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowle ...

Continue Reading
CVE-2022-29926

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation in Cybozu, Inc. showed that it was not a vulnerability. Notes: ...

Continue Reading
CVE-2022-31547

The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.Read More ...

Continue Reading
CVE-2022-30792

In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are no ...

Continue Reading
CVE-2022-2368

Business Logic Errors in GitHub repository microweber/microweber prior to 1.2.20.Read More ...

Continue Reading
CVE-2022-31545

The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.Read More ...

Continue Reading
CVE-2022-31565

The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.Read More ...

Continue Reading
CVE-2022-31566

The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: