NA - CVE-2024-50691 - SunGrow iSolarCloud Android app V2.1.6.20241104...
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers...
NA - CVE-2024-50696 - SunGrow WiNet-S V200.001.00.P025 and earlier...
SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity...
NA - CVE-2024-57423 - A Cross Site Scripting vulnerability in...
A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.
NA - CVE-2024-53573 - Unifiedtransform v2.X is vulnerable to...
Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects...
NA - CVE-2024-55581 - When AdaCore Ada Web Server 25.0.0 is linked...
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's...
NA - CVE-2024-57040 - TL-WR845N(UN)_V4_200909 and...
TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained via a brute force attack.
NA - CVE-2025-1728 - Rejected reason: ** REJECT ** DO NOT USE THIS...
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent...