Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-48230 SQL Injection vulnerability in Funadmin 5.0.2
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
network
low complexity
funadmin CWE-89
7.2
2024-10-25 CVE-2024-49767 Allocation of Resources Without Limits or Throttling vulnerability in Palletsprojects Werkzeug
Werkzeug is a Web Server Gateway Interface web application library.
network
low complexity
palletsprojects CWE-770
7.5
2024-10-25 CVE-2024-37844 Cross-site Scripting vulnerability in Radixiot Mango
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
network
low complexity
radixiot CWE-79
5.4
2024-10-25 CVE-2024-37845 OS Command Injection vulnerability in Radixiot Mango
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
network
low complexity
radixiot CWE-78
7.2
2024-10-25 CVE-2024-37846 Code Injection vulnerability in Radixiot Mango
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
network
low complexity
radixiot CWE-94
4.6
2024-10-25 CVE-2024-37847 Path Traversal vulnerability in Radixiot Mango and Mangoapi
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
network
low complexity
radixiot CWE-22
8.8
2024-10-25 CVE-2024-9584 Missing Authorization vulnerability in Webcraftplugins Image MAP PRO
The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the AJAX functions in versions up to, and including, 6.0.20.
network
low complexity
webcraftplugins CWE-862
5.4
2024-10-25 CVE-2024-9585 Cross-site Scripting vulnerability in Webcraftplugins Image MAP PRO
The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, and including, 6.0.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
webcraftplugins CWE-79
5.4
2024-10-25 CVE-2022-30356 Incorrect Authorization vulnerability in Ovaledge
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters .
network
low complexity
ovaledge CWE-863
4.7
2024-10-25 CVE-2022-30357 Unspecified vulnerability in Ovaledge
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters.
network
low complexity
ovaledge
8.8