Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2024
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-01-09
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
CVSS Score
5.5
EPSS Score
0.0
Published
2024-01-09
An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.
CVSS Score
9.6
EPSS Score
0.007
Published
2024-01-09
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate administrator logs in.
CVSS Score
9.8
EPSS Score
0.008
Published
2024-01-09
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.
CVSS Score
5.4
EPSS Score
0.007
Published
2024-01-09
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the application.
CVSS Score
3.7
EPSS Score
0.002
Published
2024-01-09
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This could allow an attacker with high privileges to perform unintended actions, resulting in escalation of privileges, which has High impact on confidentiality, integrity and availability of the system.
CVSS Score
7.3
EPSS Score
0.001
Published
2024-01-09
juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.
CVSS Score
4.9
EPSS Score
0.001
Published
2024-01-09
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
CVSS Score
9.8
EPSS Score
0.269
Published
2024-01-09
Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution. This vulnerability has been patched in release 2024-01-01.
CVSS Score
9.8
EPSS Score
0.026
Published
2024-01-09


Contact Us

Shodan ® - All rights reserved