Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-22 CVE-2024-47221 Weak Password Requirements vulnerability in Rapidscada Rapid Scada
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
network
low complexity
rapidscada CWE-521
7.5
2024-09-22 CVE-2024-9076 Command Injection vulnerability in Dedecms
A vulnerability was found in DedeCMS up to 5.7.115.
network
low complexity
dedecms CWE-77
8.8
2024-09-21 CVE-2024-9075 Cross-site Scripting vulnerability in Stirlingpdf Stirling PDF
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3.
network
low complexity
stirlingpdf CWE-79
5.4
2024-09-21 CVE-2024-8680 Cross-site Scripting vulnerability in Ibericode Mailchimp
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insufficient input sanitization and output escaping.
network
low complexity
ibericode CWE-79
5.5
2024-09-21 CVE-2024-9048 Cross-site Scripting vulnerability in Ruoyi
A vulnerability was found in y_project RuoYi up to 4.7.9.
network
low complexity
ruoyi CWE-79
6.1
2024-09-21 CVE-2024-6785 Cleartext Storage of Sensitive Information vulnerability in Moxa Mxview ONE and Mxview ONE Central Manager
The configuration file stores credentials in cleartext.
local
low complexity
moxa CWE-312
7.1
2024-09-21 CVE-2024-6786 Path Traversal vulnerability in Moxa Mxview ONE
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system.
network
low complexity
moxa CWE-22
6.5
2024-09-21 CVE-2024-6787 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Moxa Mxview ONE
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU).
network
high complexity
moxa CWE-367
5.9
2024-09-20 CVE-2024-9040 Cleartext Storage of Sensitive Information vulnerability in Code-Projects Blood Bank Management System 1.0
A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0.
local
low complexity
code-projects CWE-312
5.5
2024-09-20 CVE-2024-9041 SQL Injection vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical.
network
low complexity
mayurik CWE-89
8.8