Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sdk vulnerabilities and exploits
(subscribe to this query)
10
CVSSv3
CVE-2017-14378
EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow malicious users to bypass authentication, aka an "Error Handling Vulnerability."
Emc Rsa Authentication Agent Sdk For C 8.6
Emc Rsa Authentication Agent Api For C 8.5
1 Article
9.8
CVSSv3
CVE-2023-4280
An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and previous versions of the Gecko SDK allows an malicious user to access the trusted region of memory from the untrusted region.
Silabs Gecko Software Development Kit
9.8
CVSSv3
CVE-2023-4489
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and previous versions. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unautho...
Silabs Z\\/ip Gateway Sdk
9.8
CVSSv3
CVE-2023-0757
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote malicious user to upload arbitrary malicious code and gain full access on the affected device.
Phoenixcontact Multiprog
Phoenixcontact Proconos Eclr
9.8
CVSSv3
CVE-2022-40609
IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote malicious user to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code o...
Ibm Sdk
9.8
CVSSv3
CVE-2023-2686
Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.
Silabs Gecko Software Development Kit
9.8
CVSSv3
CVE-2018-25082
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipulation leads to xml external entity reference. The attack may be initiated remotely. Upgrading to version 0.5.5 is able to address th...
Wechat Sdk Python Project Wechat Sdk Python
9.8
CVSSv3
CVE-2023-0754
The affected products are vulnerable to an integer overflow or wraparound, which could allow an malicious user to crash the server and remotely execute arbitrary code.
Rockwellautomation Kepserver Enterprise
Ptc Thingworx Kepware Edge
Ptc Thingworx .net-sdk
Ptc Thingworx Edge C-sdk
Ptc Thingworx Edge Microserver
Ptc Kepware Serverex
Ge Digital Industrial Gateway Server
Ptc Kepware Server
Ptc Thingworx Industrial Connectivity
9.8
CVSSv3
CVE-2023-0755
The affected products are vulnerable to an improper validation of array index, which could allow an malicious user to crash the server and remotely execute arbitrary code.
Ptc Thingworx Industrial Connectivity -
Rockwellautomation Kepserver Enterprise
Ptc Thingworx Kepware Edge
Ptc Thingworx .net-sdk
Ptc Thingworx Edge C-sdk
Ptc Thingworx Edge Microserver
Ptc Kepware Serverex
Ge Digital Industrial Gateway Server
Ptc Kepware Server
9.8
CVSSv3
CVE-2022-4725
A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-core/src/main/java/com/amazonaws/util/XpathUtils.java of the component XML Parser. The manipulation leads to server-side request forg...
Amazon Aws Software Development Kit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27977
IMAP
local users
CVE-2024-32038
CVE-2023-49963
CVE-2023-22869
CVE-2024-31497
local
CVE-2024-2961
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »