NA - CVE-2025-46704 - A vulnerability exists in Advantech iView in...
A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least...
NA - CVE-2025-48496 - Emerson ValveLink products
use a fixed or...
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
NA - CVE-2025-48891 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with...
NA - CVE-2025-52459 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges....
NA - CVE-2025-52577 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at...
NA - CVE-2025-52579 - Emerson ValveLink Products store sensitive...
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or...
NA - CVE-2025-53397 - A vulnerability exists in Advantech iView...
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute...
NA - CVE-2025-53471 - Emerson ValveLink products
receive input or...
Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
NA - CVE-2025-53475 - A vulnerability exists in Advantech iView that...
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker...