ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9921
+2 in the same advisory: …9922 …9923
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL command

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

NVD description · AI analysis pending
9.8
group max
<1%
  • teamplus team\+ pro
CVE-2022-35220
+1 in the same advisory: …35221
Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability.

Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general user privilege posting a thread with large content can cause the receiving client device to allocate too much memory, leading to abnormal termination of this client’s Teamplus Pro application.

NVD description · AI analysis pending
6.5
group max
<1%
  • teamplus team\+ pro
CVE-2022-32958
A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other recipients’ Te

A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other recipients’ Teamplus Pro chat process.

NVD description · AI analysis pending
6.5<1%
  • teamplus team\+ pro