Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2024
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.
CVSS Score
6.1
EPSS Score
0.003
Published
2024-10-30
EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.
CVSS Score
4.8
EPSS Score
0.004
Published
2024-10-30
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.
CVSS Score
8.8
EPSS Score
0.006
Published
2024-10-30
A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.
CVSS Score
6.4
EPSS Score
0.002
Published
2024-10-30
Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.
CVSS Score
5.4
EPSS Score
0.003
Published
2024-10-30
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.
CVSS Score
8.8
EPSS Score
0.004
Published
2024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.
CVSS Score
8.8
EPSS Score
0.006
Published
2024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.
CVSS Score
8.8
EPSS Score
0.006
Published
2024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.
CVSS Score
8.8
EPSS Score
0.006
Published
2024-10-30


Contact Us

Shodan ® - All rights reserved