Vulnerabilities (CVE)

Filtered by vendor Softing Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-48192 1 Softing 1 Smartlink Sw-ht 2023-11-14 N/A 6.1 MEDIUM
Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.
CVE-2021-29661 1 Softing 1 Opc Toolbox 2021-04-08 3.5 LOW 5.4 MEDIUM
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.