Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-51431 Use of Hard-coded Credentials vulnerability in Lb-Link Bl-Wr1300H Firmware 1.0.4
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
network
low complexity
lb-link CWE-798
critical
9.8
2024-11-01 CVE-2024-10659 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-11-01 CVE-2024-10660 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-11-01 CVE-2024-10661 Out-of-bounds Write vulnerability in Tenda Ac15 Firmware 15.03.05.19
A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical.
network
low complexity
tenda CWE-787
8.8
2024-11-01 CVE-2024-10662 Out-of-bounds Write vulnerability in Tenda Ac15 Firmware 15.03.05.19
A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical.
network
low complexity
tenda CWE-787
8.8
2024-11-01 CVE-2024-22733 NULL Pointer Dereference vulnerability in Tp-Link Mr200 Firmware 210201
TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.
network
low complexity
tp-link CWE-476
7.5
2024-11-01 CVE-2024-51377 Cross-site Scripting vulnerability in Ladybirdweb Faveo Helpdesk 9.2.0
An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields
network
low complexity
ladybirdweb CWE-79
5.4
2024-11-01 CVE-2024-10656 SQL Injection vulnerability in Tongda2000 Office Anywhere 2017
A vulnerability was found in Tongda OA 2017 up to 11.9.
network
low complexity
tongda2000 CWE-89
critical
9.8
2024-11-01 CVE-2024-10657 SQL Injection vulnerability in Tongda2000 Office Anywhere 11.10
A vulnerability classified as critical has been found in Tongda OA up to 11.10.
network
low complexity
tongda2000 CWE-89
critical
9.8
2024-11-01 CVE-2024-10658 SQL Injection vulnerability in Tongda2000 Office Anywhere 11.10
A vulnerability classified as critical was found in Tongda OA up to 11.10.
network
low complexity
tongda2000 CWE-89
critical
9.8