Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-12921 | In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can resu In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2026-12390 | In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can resu In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2025-66590 | In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past t In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash. NVD description · AI analysis pending | 8.4 group max | <1% |
| — | ||
| CVE-2021-42698 | Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2017-12699 +1 in the same advisory: …5147 | An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones. NVD description · AI analysis pending | 7.1 group max | <1% |
| — |