Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-10282 Out-of-bounds Write vulnerability in Tenda RX9 PRO Firmware 22.03.02.10/22.03.02.20
A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20.
network
low complexity
tenda CWE-787
8.8
2024-10-23 CVE-2024-10283 Out-of-bounds Write vulnerability in Tenda RX9 PRO Firmware 22.03.02.20
A vulnerability, which was classified as critical, has been found in Tenda RX9 and RX9 Pro 22.03.02.20.
network
low complexity
tenda CWE-787
8.8
2024-10-23 CVE-2024-10290 Unspecified vulnerability in Zzcms 2023
A vulnerability, which was classified as problematic, was found in ZZCMS 2023.
network
low complexity
zzcms
7.5
2024-10-23 CVE-2024-30122 Unspecified vulnerability in Hcltech Sametime 11.6/12.0/12.0.2
HCL Sametime is impacted by misconfigured security related HTTP headers.
network
low complexity
hcltech
5.3
2024-10-23 CVE-2024-47575 Missing Authentication for Critical Function vulnerability in Fortinet Fortimanager and Fortimanager Cloud
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
network
low complexity
fortinet CWE-306
critical
9.8
2024-10-23 CVE-2024-47901 OS Command Injection vulnerability in Siemens products
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)).
network
low complexity
siemens CWE-78
critical
9.8
2024-10-23 CVE-2024-47902 Missing Authentication for Critical Function vulnerability in Siemens products
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)).
network
low complexity
siemens CWE-306
critical
9.8
2024-10-23 CVE-2024-47903 Unspecified vulnerability in Siemens products
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)).
network
low complexity
siemens
critical
9.1
2024-10-23 CVE-2024-47904 Unspecified vulnerability in Siemens products
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)).
local
low complexity
siemens
7.8
2024-10-23 CVE-2024-49370 Unspecified vulnerability in Pimcore
Pimcore is an open source data and experience management platform.
network
low complexity
pimcore
4.9