Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2023-47618 OS Command Injection vulnerability in Tp-Link Er7206 Firmware 1.3.0
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591.
network
low complexity
tp-link CWE-78
7.2
2024-02-06 CVE-2024-1252 SQL Injection vulnerability in Tongda2000 Tongda Office Anywhere 11.10
A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9.
network
low complexity
tongda2000 CWE-89
critical
9.8
2024-02-06 CVE-2024-1253 Unrestricted Upload of File with Dangerous Type vulnerability in Byzoro Smart S40 Firmware 20240126
A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126.
network
low complexity
byzoro CWE-434
7.2
2024-02-06 CVE-2024-22331 Information Exposure vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent.
local
low complexity
ibm CWE-200
5.5
2024-02-06 CVE-2023-35188 SQL Injection vulnerability in Solarwinds Platform
SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform.
network
low complexity
solarwinds CWE-89
8.8
2024-02-06 CVE-2023-46183 Unspecified vulnerability in IBM Powervm Hypervisor
IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information.
local
low complexity
ibm
4.4
2024-02-06 CVE-2023-50395 SQL Injection vulnerability in Solarwinds Platform
SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform.
network
low complexity
solarwinds CWE-89
8.8
2024-02-06 CVE-2024-1251 SQL Injection vulnerability in Tongda2000 Office Anywhere 2017 11.9
A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10.
network
low complexity
tongda2000 CWE-89
critical
9.8
2024-02-06 CVE-2024-23344 Unspecified vulnerability in Enalean Tuleap
Tuleap is an Open Source Suite to improve management of software developments and collaboration.
network
low complexity
enalean
6.5
2024-02-06 CVE-2024-24000 Unrestricted Upload of File with Dangerous Type vulnerability in Huaxiaerp Jsherp 3.3
jshERP v3.3 is vulnerable to Arbitrary File Upload.
network
low complexity
huaxiaerp CWE-434
critical
9.8