Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2024
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
CVSS Score
9.8
EPSS Score
0.008
Published
2024-11-01
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
CVSS Score
8.8
EPSS Score
0.008
Published
2024-11-01
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
CVSS Score
8.8
EPSS Score
0.008
Published
2024-11-01
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
CVSS Score
8.8
EPSS Score
0.008
Published
2024-11-01
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
CVSS Score
8.8
EPSS Score
0.008
Published
2024-11-01
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-11-01
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
CVSS Score
7.5
EPSS Score
0.005
Published
2024-11-01
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
CVSS Score
5.9
EPSS Score
0.003
Published
2024-11-01
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system.
CVSS Score
5.3
EPSS Score
0.003
Published
2024-11-01
IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-11-01


Contact Us

Shodan ® - All rights reserved