Vulnerabilities (CVE)

Filtered by CWE-1104
Total 7 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48862 2025-08-14 N/A 7.1 HIGH
Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains unencrypted.
CVE-2025-3497 2025-07-10 N/A 8.7 HIGH
The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product.
CVE-2025-40906 2025-05-19 N/A 9.8 CRITICAL
BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.
CVE-2022-46871 2 Debian, Mozilla 2 Debian Linux, Firefox 2025-04-15 N/A 8.8 HIGH
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
CVE-2024-11999 2024-12-17 N/A 8.8 HIGH
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
CVE-2024-35252 1 Microsoft 1 Azure Storage Data Movement Library 2024-11-21 N/A 7.5 HIGH
Azure Storage Movement Client Library Denial of Service Vulnerability
CVE-2024-8885 2024-10-04 N/A 8.8 HIGH
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.