| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information disclosure. This issue affects Regesta Smart HD-PLC - TLDPH16D2:
11.02.05.10.02. |
| Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS) payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2:
11.02.05.10.02. |
| Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. |
| Unauthenticated Local File Inclusion in Kastell <= 2.0 versions. |
| Unauthenticated PHP Object Injection in Moderno < 1.43 versions. |
| Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. |
| Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. |
| Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. |
| Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. |
| Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. |
| Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. |
| Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. |
| Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. |
| Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. |
| Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. |
| Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. |
| Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. |