Vulnerabilities (CVE)

Filtered by vendor Xarrow Subscribe
Filtered by product Xarrow
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-33021 1 Xarrow 1 Xarrow 2022-05-25 4.3 MEDIUM 6.1 MEDIUM
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
CVE-2021-33001 1 Xarrow 1 Xarrow 2022-05-25 4.3 MEDIUM 6.1 MEDIUM
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.