Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Scriptcase HIGH 8.0
CVE-2024-46080

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Fix: after 9.10.023
Fix from $1,950 2024-10-01
Scriptcase HIGH 8.0
CVE-2024-46084

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Fix: after 9.10.023
Fix from $1,950 2024-10-01
Scriptcase MEDIUM 5.4
CVE-2024-46082

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

Fix: after 9.10.023
Fix from $1,600 2024-10-01
Scriptcase MEDIUM 5.4
CVE-2024-46083

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages fe…

Fix: after 9.10.023
Fix from $1,600 2024-10-01
Scriptcase MEDIUM 6.1
CVE-2024-46079

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.

Fix: after 9.10.023
Fix from $1,600 2024-10-01
Scriptcase MEDIUM 5.4
CVE-2024-46081

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. Th…

Fix: after 9.10.023
Fix from $1,600 2024-10-01
Scriptcase CRITICAL 9.8
CVE-2024-8940

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plu…

Mitigation only
Fix from $2,300 2024-09-25
Scriptcase HIGH 8.2
CVE-2024-8942

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_for…

Mitigation only
Fix from $1,950 2024-09-25
Scriptcase MEDIUM 5.3
CVE-2024-8941

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allo…

Mitigation only
Fix from $1,600 2024-09-25
Scriptcase MEDIUM 6.5
CVE-2022-32199

db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file para…

Fix: after 9.9.008
Fix from $1,600 2023-03-27