Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2024
An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component of the administrative web interface.
CVSS Score
8.8
EPSS Score
0.004
Published
2024-01-16
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
CVSS Score
7.8
EPSS Score
0.0
Published
2024-01-16
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-01-16
Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-01-16
An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.
CVSS Score
6.5
EPSS Score
0.006
Published
2024-01-16
SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.
CVSS Score
8.8
EPSS Score
0.11
Published
2024-01-16
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
CVSS Score
6.1
EPSS Score
0.103
Published
2024-01-16
Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.
CVSS Score
4.6
EPSS Score
0.001
Published
2024-01-16
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-01-16
SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module.
CVSS Score
7.5
EPSS Score
0.048
Published
2024-01-16


Contact Us

Shodan ® - All rights reserved