|
308191
|
9.8 |
CRITICAL
Network
|
riello-ups
|
netman_204_firmware
|
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204:…
|
CWE-89
SQL Injection
|
CVE-2024-8877
|
2024-10-1 00:31 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308192
|
5.4 |
MEDIUM
Network
|
stirlingpdf
|
stirling_pdf
|
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. The manipulation …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9075
|
2024-10-1 00:27 |
2024-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308193
|
9.8 |
CRITICAL
Network
|
riello-ups
|
netman_204_firmware
|
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: throu…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2024-8878
|
2024-10-1 00:21 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308194
|
4.6 |
MEDIUM
Physics
|
proges
|
sensor_net_connect_firmware_v2
|
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-3082
|
2024-10-1 00:15 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308195
|
5.5 |
MEDIUM
Local
|
proges
|
thermoscan_ip
|
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition o…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-31203
|
2024-10-1 00:15 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308196
|
7.8 |
HIGH
Local
|
proges
|
thermoscan_ip
|
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2024-31202
|
2024-10-1 00:15 |
2024-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308197
|
5.4 |
MEDIUM
Network
|
anwp
|
football_leagues
|
The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8917
|
2024-09-30 23:30 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308198
|
4.3 |
MEDIUM
Network
|
wedevs
|
happy_addons_for_elementor
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possibl…
|
NVD-CWE-noinfo
|
CVE-2024-8801
|
2024-09-30 23:23 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308199
|
7.5 |
HIGH
Network
|
boldgrid
|
w3_total_cache
|
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visibl…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2023-5359
|
2024-09-30 23:19 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308200
|
6.5 |
MEDIUM
Network
|
kimhuebel
|
blogintroduction-wordpress-plugin
|
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them vi…
|
CWE-352
Origin Validation Error
|
CVE-2024-7862
|
2024-09-30 23:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|