Medium - CVE-2024-9895 - The Smart Online Order for Clover plugin for...
The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due...
NA - CVE-2024-9925 - SQL injection vulnerability in TAI Smart...
SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a...
High - CVE-2024-9983 - Enterprise Cloud Database from Ragic does not...
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
Critical - CVE-2024-9984 - Enterprise Cloud Database from Ragic does not...
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session...
Critical - CVE-2024-9985 - Enterprise Cloud Database from Ragic does not...
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote...
NA - CVE-2024-47945 - The devices are vulnerable to session hijacking...
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user,...
NA - CVE-2024-9973 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports of the component Report...
NA - CVE-2024-9974 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file...
High - CVE-2024-45272 - An unauthenticated remote attacker can perform...
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.