CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “festo”

9 vulnerabilities found for “festo”

CVE-2023-4297
MEDIUM4.3

The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.

mediamanifesto / mmm_simple_file_list
Network
Published Nov 27, 2023
CVE-2023-4514
MEDIUM5.4

The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

mediamanifesto / mmm_simple_file_list
Network
Published Nov 27, 2023
CVE-2020-12069
HIGH7.8

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

pilz / pmc+66
Local
Published Dec 26, 2022
CVE-2022-3270
CRITICAL9.8

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

festo / bus_module_cpx-e-ep_firmware+98
Network
Published Dec 1, 2022
CVE-2022-3079
HIGH7.5

Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.

festo / cpx-cmxx_firmware+1
Network
Published Sep 20, 2022
CVE-2022-30308
CRITICAL9.8

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

festo / controller_cecc-x-m1_firmware+10
Network
Published Jun 13, 2022
CVE-2022-30309
CRITICAL9.8

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

festo / controller_cecc-x-m1_firmware+10
Network
Published Jun 13, 2022
CVE-2022-30310
CRITICAL9.8

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

festo / controller_cecc-x-m1_firmware+10
Network
Published Jun 13, 2022
CVE-2022-30311
CRITICAL9.8

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

festo / controller_cecc-x-m1_firmware+10
Network
Published Jun 13, 2022