Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-10440 SQL Injection vulnerability in Sun.Net Ehdr Ctms
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.
network
low complexity
sun-net CWE-89
critical
9.8
2024-10-28 CVE-2024-10434 Out-of-bounds Write vulnerability in Tenda Ac1206 Firmware 1.0/15.03.06.23/15.03.06.23Multitd01
A vulnerability was found in Tenda AC1206 up to 20241027.
network
low complexity
tenda CWE-787
critical
9.8
2024-10-28 CVE-2024-50067 Out-of-bounds Write vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetching args Uprobe needs to fetch args into a percpu buffer, and then copy to ring buffer to avoid non-atomic context problem. Sometimes user-space strings, arrays can be very large, but the size of percpu buffer is only page size.
local
low complexity
linux CWE-787
7.8
2024-10-28 CVE-2024-10432 SQL Injection vulnerability in Projectworlds Simple Web-Based Chat Application 1.0
A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical.
network
low complexity
projectworlds CWE-89
critical
9.8
2024-10-28 CVE-2024-10433 Cross-site Scripting vulnerability in Projectworlds Simple Web-Based Chat Application 1.0
A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic.
network
low complexity
projectworlds CWE-79
6.1
2024-10-28 CVE-2024-50623 Unrestricted Upload of File with Dangerous Type vulnerability in Cleo Harmony, Lexicom and Vltrader
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
network
low complexity
cleo CWE-434
critical
9.8
2024-10-27 CVE-2024-10430 SQL Injection vulnerability in Codezips PET Shop Management System 1.0
A vulnerability, which was classified as critical, has been found in Codezips Pet Shop Management System 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-27 CVE-2024-10431 SQL Injection vulnerability in Codezips PET Shop Management System 1.0
A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-27 CVE-2024-50612 Out-of-bounds Read vulnerability in Libsndfile Project Libsndfile
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
local
low complexity
libsndfile-project CWE-125
5.5
2024-10-27 CVE-2024-50613 Reachable Assertion vulnerability in Libsndfile Project Libsndfile
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
network
low complexity
libsndfile-project CWE-617
6.5