Latest CVE Feed
-
9.8
CRITICALCVE-2025-6845
A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the argument User leads to sql injection. The attack may be la... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2012-6442
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of ava... Read more
Affected Products : 1756-enbt 1756-eweb 1768-enbt 1768-eweb ethernet\/ip_firmware compactlogix_firmware flexlogix_firmware flex_i\/o_ethernet\/ip__firmware micrologix_firmware compactlogix_controllers_firmware +12 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
5.0
MEDIUMCVE-2012-6441
An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confi... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
9.3
HIGHCVE-2012-6440
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configurati... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
8.5
HIGHCVE-2012-6439
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occ... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
7.8
HIGHCVE-2012-6438
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successfu... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
10.0
HIGHCVE-2012-6437
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
7.8
HIGHCVE-2012-6436
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successfu... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
7.8
HIGHCVE-2012-6435
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. Thi... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
6.1
MEDIUMCVE-2022-36350
Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : pukiwiki- Published: Aug. 23, 2022
- Modified: Jun. 30, 2025
-
5.4
MEDIUMCVE-2020-35509
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality ... Read more
- Published: Aug. 23, 2022
- Modified: Jun. 30, 2025
-
4.8
MEDIUMCVE-2025-6494
A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as problematic. This affects the function hashmap_get_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-bas... Read more
Affected Products : nokogiri- Published: Jun. 22, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-6490
A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based ... Read more
Affected Products : nokogiri- Published: Jun. 22, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-53621
A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-47310
A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Misconfiguration
-
8.0
HIGHCVE-2023-28909
A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can lev... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2023-28908
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vul... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2023-28907
There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered i... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2023-28906
A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system. The vulnerability was originally discovered in Skoda Superb I... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2023-28905
A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V00358... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption