5.3
CVE-2024-9974 - SourceCodester Online Eyewear Shop POST Request Master.php sql injection
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=add_to_card of the component POST Request Handler. The manipulation of the argument product_id leads to โฆ
5.3
CVE-2024-9973 - SourceCodester Online Eyewear Shop Report Viewing Page page sql injection
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports of the component Report Viewing Page. The manipulation of the argument date leads to sql injection. It is possible to launch the โฆ
6.8
CVE-2024-47944 - Missing Protection Mechanism for Alternate Hardware Interface
The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via theย firmware upgrade function.
9.8
CVE-2024-47943 - Improper signature verification of firmware upgrade files
The firmware upgrade function in the admin web interface of the Rittalย IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the fโฆ
9.8
CVE-2024-9925 - SQL injection in QPLANT by TAI Smart Factory
SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the โemailโ parameter on the โRequestPasswordChangeโ endpoint.
6.4
CVE-2024-9895 - Smart Online Order for Clover <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting vโฆ
The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โฆ
10
CVE-2024-9985 - Ragic Enterprise Cloud Database - Arbitrary File Upload
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
9.8
CVE-2024-9984 - Ragic Enterprise Cloud Database - Missing Authentication
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
7.5
CVE-2024-9983 - Ragic Enterprise Cloud Database - Arbitrary File Read through Path Traversal
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
9.8
CVE-2024-9982 - ESi Technology AIM LINE Marketing Platform - SQL Injection
AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.