Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2022-2104
The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
CRITICAL 9.1
CVE-2022-2103
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely …
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
CRITICAL 9.1
CVE-2022-2105
Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level mean…
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
HIGH 7.5
CVE-2022-2102
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response…
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
CRITICAL 9.8
CVE-2022-1668
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
HIGH 7.5
CVE-2022-1667
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading th…
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+
MEDIUM 6.5
CVE-2022-1666
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password usin…
Sepcos Control And Protection Relay Firmware
1.23.21 / 1.24.8+