Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8877 SQL Injection vulnerability in Riello-Ups Netman 204 Firmware 02.05
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204.
network
low complexity
riello-ups CWE-89
critical
9.8
2024-09-25 CVE-2024-8878 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Riello-Ups Netman 204 Firmware 02.05
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
network
low complexity
riello-ups CWE-640
critical
9.8
2024-09-25 CVE-2024-8914 The Thanh Toán Quét Mã QR Code T? ??ng – MoMo, ViettelPay, VNPay và 40 ngân hàng Vi?t Nam plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation.
network
low complexity
7.2
2024-09-25 CVE-2024-8917 Cross-site Scripting vulnerability in Anwp Football Leagues
The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 due to insufficient input sanitization and output escaping.
network
low complexity
anwp CWE-79
5.4
2024-09-25 CVE-2024-8919 Cross-site Scripting vulnerability in Wpdeveloperr Confetti Fall Animation
The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpdeveloperr CWE-79
5.4
2024-09-25 CVE-2024-8940 Unrestricted Upload of File with Dangerous Type vulnerability in Scriptcase 9.4.019
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request.
network
low complexity
scriptcase CWE-434
critical
9.8
2024-09-25 CVE-2024-8941 Path Traversal vulnerability in Scriptcase 9.4.019
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.
network
low complexity
scriptcase CWE-22
5.3
2024-09-25 CVE-2024-8942 Cross-site Scripting vulnerability in Scriptcase 9.4.019
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others.
network
low complexity
scriptcase CWE-79
8.2
2024-09-25 CVE-2024-9148 Cross-site Scripting vulnerability in Flowiseai Embed and Flowise
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
network
low complexity
flowiseai CWE-79
6.1
2024-09-24 CVE-2024-8623 Code Injection vulnerability in Pluginus Wordpress Meta Data and Taxonomies Filter
The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3.
network
low complexity
pluginus CWE-94
7.3