5.3

CVSS4.0

CVE-2024-9974 - SourceCodester Online Eyewear Shop POST Request Master.php sql injection

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=add_to_card of the component POST Request Handler. The manipulation of the argument product_id leads to โ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2024, 7:28 p.m.

5.3

CVSS4.0

CVE-2024-9973 - SourceCodester Online Eyewear Shop Report Viewing Page page sql injection

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports of the component Report Viewing Page. The manipulation of the argument date leads to sql injection. It is possible to launch the โ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2024, 7:27 p.m.

6.8

CVSS3.1

CVE-2024-47944 - Missing Protection Mechanism for Alternate Hardware Interface

The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via theย firmware upgrade function.

๐Ÿ“… Published: Oct. 15, 2024, 9 a.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

9.8

CVSS3.1

CVE-2024-47943 - Improper signature verification of firmware upgrade files

The firmware upgrade function in the admin web interface of the Rittalย IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the fโ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 8:57 a.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

9.8

CVSS3.1

CVE-2024-9925 - SQL injection in QPLANT by TAI Smart Factory

SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the โ€˜emailโ€™ parameter on the โ€˜RequestPasswordChangeโ€™ endpoint.

๐Ÿ“… Published: Oct. 15, 2024, 8:41 a.m. ๐Ÿ”„ Last Modified: Oct. 17, 2024, 6:09 p.m.

6.4

CVSS3.1

CVE-2024-9895 - Smart Online Order for Clover <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting vโ€ฆ

The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โ€ฆ

๐Ÿ“… Published: Oct. 15, 2024, 8:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:30 p.m.

10

CVSS3.1

CVE-2024-9985 - Ragic Enterprise Cloud Database - Arbitrary File Upload

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.

๐Ÿ“… Published: Oct. 15, 2024, 8:20 a.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 10:02 p.m.

9.8

CVSS3.1

CVE-2024-9984 - Ragic Enterprise Cloud Database - Missing Authentication

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.

๐Ÿ“… Published: Oct. 15, 2024, 8:15 a.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 10:03 p.m.

7.5

CVSS3.1

CVE-2024-9983 - Ragic Enterprise Cloud Database - Arbitrary File Read through Path Traversal

Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

๐Ÿ“… Published: Oct. 15, 2024, 8:12 a.m. ๐Ÿ”„ Last Modified: Oct. 16, 2024, 10:03 p.m.

9.8

CVSS3.1

CVE-2024-9982 - ESi Technology AIM LINE Marketing Platform - SQL Injection

AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.

๐Ÿ“… Published: Oct. 15, 2024, 8:04 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2024, 1:50 p.m.
Total resulsts: 344111
Page 7785 of 34,412
ยซ previous page ยป next page
Filters