6.7

CVSS3.1

CVE-2023-29122 - Incorrect file ownership of privileged service's libraries in Enel X JuiceBox

Under certain conditions, access to service libraries is granted to account they should not have access to.

📅 Published: Nov. 5, 2024, 3:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2023-29121 - Exposed TCF agent service in Enel X Juicebox

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

📅 Published: Nov. 5, 2024, 3:23 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29120 - Unauthorized Remote Command Execution in Enel X Juicebox

Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.

📅 Published: Nov. 5, 2024, 3:22 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29119 - Unauthorized SQLite Injection

Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.

📅 Published: Nov. 5, 2024, 3:20 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29118 - Unauthorized SQLite Injection in Enel X Juicebox

Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.

📅 Published: Nov. 5, 2024, 3:18 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:08 p.m.

8.8

CVSS3.1

CVE-2023-29117 - Authentication Bypass in JuiceBox Web Manager interface

Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.

📅 Published: Nov. 5, 2024, 3:14 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:08 p.m.

4.3

CVSS3.1

CVE-2023-29116 - PHP Information Disclosure in Enel X JuiceBox

Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.

📅 Published: Nov. 5, 2024, 3:08 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:08 p.m.

6.5

CVSS3.1

CVE-2023-29115 - Denial of Service via Web Management interface in Enel X JuiceBox

In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

📅 Published: Nov. 5, 2024, 3:04 p.m. 🔄 Last Modified: Nov. 8, 2024, 4:08 p.m.

5.7

CVSS3.1

CVE-2023-29114 - Unauthorized System Log Disclosure in Enel X JuiceBox

System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: •     Wi-Fi access point credentials to which the EV charger can connect. •     APN web address and credentials. •     IPSEC credentials…

📅 Published: Nov. 5, 2024, 3:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-10845 - 1000 Projects Bookstore Management System book_detail.php sql injection

A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been dis…

📅 Published: Nov. 5, 2024, 3 p.m. 🔄 Last Modified: March 23, 2026, 4:32 p.m.
Total resulsts: 346616
Page 7757 of 34,662
« previous page » next page
Filters