Vulnerabilities
20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-47134 | Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2024-6737 | The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regula The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-5950 | Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of multipart form variables. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23172. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2023-2872 | A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229851. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2023-1151 | A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the component Cookie Handler. The manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222163. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-45914 | The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use aut The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use authentication, which allows attackers to change label values via 433 MHz RF signals, as demonstrated by disrupting the organization of a hospital storage unit, or changing retail pricing. NVD description · AI analysis pending | 6.5 | <1% | PoC ×3 |
| — | |
| CVE-2022-2693 | A vulnerability has been found in SourceCodester Electronic Medical Records System and classified as critical. A vulnerability has been found in SourceCodester Electronic Medical Records System and classified as critical. This vulnerability affects unknown code of the file register.php of the component UPDATE Statement Handler. The manipulation of the argument pconsultation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205816. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-2676 | A vulnerability was found in SourceCodester Electronic Medical Records System and classified as critical. A vulnerability was found in SourceCodester Electronic Medical Records System and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument user_email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205664. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-26131 +1 in the same advisory: …25922 | Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2021-38406 | Out-of-Bounds Write Code Execution in Delta Electronics DOPSoft 2 Project File Parsing Delta Electronics DOPSoft 2 (version 2.00.07 and prior) fails to properly validate user-supplied data when parsing project files, resulting in multiple out-of-bounds write vulnerabilities (CWE-787). Because the flaw requires local access and user interaction, exploitation typically involves tricking an engineer or operator into opening a maliciously crafted DOPSoft project file. Successful exploitation lets the attacker execute code in the context of the current process, i.e., as the logged-in user of the workstation running DOPSoft, which in OT environments is typically an engineering workstation with access to the control network. Only users still running the end-of-life DOPSoft 2 branch are affected; owners of Delta HMI deployments who have not migrated off this older configuration tool are in scope. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-25 as part of a batch of 10 additions, confirming active exploitation in the wild, and it carries a very high EPSS score of 76.4% (100th percentile), though no public proof-of-concept is known and ransomware use is unknown. Do: Inventory engineering, maintenance, and other control-network-connected workstations for DOPSoft 2 (version 2.00.07 or earlier); per CISA's required action, stop using or disconnect the end-of-life DOPSoft 2 and migrate to a currently supported DOPSoft release where configuration software is still needed (no fixed version is specified in the available data). Until remediated, do not open DOPSoft project files from untrusted sources (email, downloads, removable media) on stations that have access to control networks. | 7.8 | 76% | KEV |
| moderate~10,000-100,000 engineering workstations worldwide (rough estimate; no public install counts exist) | |
| CVE-2019-12797 | A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle. A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2017-5909 | The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attac The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NVD description · AI analysis pending | 5.9 | <1% |
| — | ||
| CVE-2016-5805 +1 in the same advisory: …5802 | An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service. NVD description · AI analysis pending | 7.8 | 2% |
| — |