Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-9147 Cross-site Scripting vulnerability in BNA Pospratik
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects PosPratik: before v3.2.1.
network
low complexity
bna CWE-79
6.1
2024-11-04 CVE-2024-10035 Code Injection vulnerability in Bg-Tek Coslat
Improper Control of Generation of Code ('Code Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection.This issue affects CoslatV3: through 3.1069.
network
low complexity
bg-tek CWE-94
critical
9.8
2024-11-04 CVE-2024-10523 Cleartext Storage of Sensitive Information vulnerability in Tp-Link Tapo H100 Firmware
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware.
low complexity
tp-link CWE-312
4.6
2024-11-04 CVE-2024-36485 SQL Injection vulnerability in Zohocorp Manageengine Adaudit Plus
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
network
low complexity
zohocorp CWE-89
8.8
2024-11-04 CVE-2024-48878 SQL Injection vulnerability in Zohocorp Manageengine Admanager Plus
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
network
low complexity
zohocorp CWE-89
8.8
2024-11-04 CVE-2024-51661 OS Command Injection vulnerability in Davidlingren Media Library Assistant
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.
network
low complexity
davidlingren CWE-78
7.2
2024-11-04 CVE-2024-23377 Unspecified vulnerability in Qualcomm products
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
local
low complexity
qualcomm
6.7
2024-11-04 CVE-2024-23385 Reachable Assertion vulnerability in Qualcomm products
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
network
low complexity
qualcomm CWE-617
6.5
2024-11-04 CVE-2024-23386 Unspecified vulnerability in Qualcomm products
memory corruption when WiFi display APIs are invoked with large random inputs.
local
low complexity
qualcomm
6.7
2024-11-04 CVE-2024-33029 Use After Free vulnerability in Qualcomm products
Memory corruption while handling the PDR in driver for getting the remote heap maps.
local
low complexity
qualcomm CWE-416
6.7