Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-20 CVE-2024-49616 SQL Injection vulnerability in Nyasro Rate OWN Post
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nyasro Rate Own Post allows Blind SQL Injection.This issue affects Rate Own Post: from n/a through 1.0.
network
low complexity
nyasro CWE-89
8.8
2024-10-20 CVE-2024-49617 Cross-Site Request Forgery (CSRF) vulnerability in Bhaskardhote Back Link Tracker
Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Back Link Tracker allows Blind SQL Injection.This issue affects Back Link Tracker: from n/a through 1.0.0.
network
low complexity
bhaskardhote CWE-352
8.8
2024-10-20 CVE-2024-49618 SQL Injection vulnerability in Jordanlyall Mytweetlinks
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordan Lyall MyTweetLinks allows Blind SQL Injection.This issue affects MyTweetLinks: from n/a through 1.1.1.
network
low complexity
jordanlyall CWE-89
8.8
2024-10-20 CVE-2024-49619 SQL Injection vulnerability in Acespritech Social Link Groups
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Acespritech Solutions Pvt.
network
low complexity
acespritech CWE-89
8.8
2024-10-20 CVE-2024-49620 SQL Injection vulnerability in Naudinvladimir Ferma.Ru.Net
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Naudin Vladimir FERMA.Ru.Net allows Blind SQL Injection.This issue affects FERMA.Ru.Net: from n/a through 1.3.3.
network
low complexity
naudinvladimir CWE-89
8.8
2024-10-20 CVE-2024-49629 Cross-Site Request Forgery (CSRF) vulnerability in Androidbubbles Endless Posts Navigation
Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.
network
low complexity
androidbubbles CWE-352
6.1
2024-10-20 CVE-2024-10195 SQL Injection vulnerability in Tecno-Mobile 4G Portable Wifi Tr118 Firmware V00820220830
A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830.
network
low complexity
tecno-mobile CWE-89
critical
9.8
2024-10-20 CVE-2024-49324 Unrestricted Upload of File with Dangerous Type vulnerability in Sovratec Case Management
Unrestricted Upload of File with Dangerous Type vulnerability in Sovratec Sovratec Case Management allows Upload a Web Shell to a Web Server.This issue affects Sovratec Case Management: from n/a through 1.0.0.
network
low complexity
sovratec CWE-434
critical
9.8
2024-10-20 CVE-2024-49326 Unrestricted Upload of File with Dangerous Type vulnerability in Vasiliskerasiotis Affiliator
Unrestricted Upload of File with Dangerous Type vulnerability in Vasilis Kerasiotis Affiliator allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through 2.1.3.
network
low complexity
vasiliskerasiotis CWE-434
critical
9.8
2024-10-20 CVE-2024-49327 Unrestricted Upload of File with Dangerous Type vulnerability in Asepbagjapriandana Woostagram Connect
Unrestricted Upload of File with Dangerous Type vulnerability in Asep Bagja Priandana Woostagram Connect allows Upload a Web Shell to a Web Server.This issue affects Woostagram Connect: from n/a through 1.0.2.
network
low complexity
asepbagjapriandana CWE-434
critical
9.8