NA - CVE-2024-50685 - SunGrow iSolarCloud before the October 31, 2024...
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model.
NA - CVE-2024-50688 - SunGrow iSolarCloud Android application...
SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for...
NA - CVE-2024-50691 - SunGrow iSolarCloud Android app V2.1.6.20241104...
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers...
NA - CVE-2024-50696 - SunGrow WiNet-S V200.001.00.P025 and earlier...
SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity...
NA - CVE-2024-57423 - A Cross Site Scripting vulnerability in...
A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.
NA - CVE-2024-53573 - Unifiedtransform v2.X is vulnerable to...
Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects...