Posts of last 24 hours
A vulnerability identified as problematic has been detected in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. The impacted element is an unknown function of the component Operation Web Application. This manipulation causes cross-site request forgery.
This vulnerability is registered as CVE-2022-40179. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/210416
A vulnerability labeled as problematic has been found in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. This affects an unknown function of the component Operation Web Application. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2022-40180. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/210417
A vulnerability classified as problematic was found in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. Affected by this issue is some unknown functionality of the component Device Embedded Browser. The manipulation results in improper neutralization of encoded uri schemes in a web page.
This vulnerability is known as CVE-2022-40181. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/210421
A vulnerability categorized as problematic has been discovered in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. The affected element is an unknown function of the component Operation Web Application. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2022-40178. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/210415
微软在一篇博客文章中透露,其已开始测试一种广告支持的方式来串流你游戏库中的游戏。这个新选项将允许玩家无需支付费用即可串流游戏。玩家无需付费,而是在游玩环节开始前观看广告。观看完毕后,他们随后将被允许串
https://buaq.net/go-430623.html
A vulnerability was found in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. It has been rated as very critical. Impacted is an unknown function of the component Operation Web Application. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2022-40177. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/210414
A vulnerability marked as critical has been reported in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. This impacts an unknown function. Performing a manipulation results in os command injection.
This vulnerability is reported as CVE-2022-40176. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/210418
A vulnerability labeled as critical has been found in Siemens Industrial Edge Management up to 1.5.0. Affected by this vulnerability is an unknown functionality of the component TLS Connection Handler. Executing a manipulation can lead to improper certificate validation.
This vulnerability is registered as CVE-2022-40147. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/210431
Эксперименты показали, что кое в чем компьютерные психологи преуспели больше нас.
https://www.securitylab.ru/news/575220.php
Here’s a look at the most interesting products from the past week, featuring releases from Astelia, Druva, Swimlane, and ThreatDown. Druva brings backup, recovery and governance to AI workloads Druva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Protocol (MCP), and Dru SRE Agent for … More →
The post New infosec products of the week: July 24, 2026 appeared first on Help Net Security.
https://www.helpnetsecurity.com/2026/07/24/new-infosec-products-of-the-week-july-24-2026/