Vulnerabilities > Voltronicpower

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-49563 Cross-site Scripting vulnerability in Voltronicpower Snmp web PRO 1.1
Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver.
network
low complexity
voltronicpower CWE-79
6.1
2023-09-12 CVE-2023-39073 Missing Authorization vulnerability in Voltronicpower Snmp web PRO 1.1
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.
network
low complexity
voltronicpower CWE-862
critical
9.8
2023-07-12 CVE-2023-33274 Improper Authentication vulnerability in Voltronicpower Snmp web PRO 1.1
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization.
network
low complexity
voltronicpower CWE-287
critical
9.8