Search
Search Results (24 CVEs found)
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-29661 | 1 Softing | 1 Opc Toolbox | 2024-11-21 | 5.4 Medium |
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it. | ||||
CVE-2021-29660 | 1 Softing | 1 Opc Toolbox | 2024-11-21 | 8.8 High |
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker. | ||||
CVE-2020-14524 | 1 Softing | 1 Opc | 2024-11-21 | 9.8 Critical |
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. | ||||
CVE-2020-14522 | 1 Softing | 1 Opc | 2024-11-21 | 7.5 High |
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition. |