Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-20 CVE-2024-9032 Path Traversal vulnerability in Oretnom23 Simple Forum/Discussion System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0.
network
low complexity
oretnom23 CWE-22
8.8
2024-09-20 CVE-2024-9030 Cross-site Scripting vulnerability in Workdo Crmgo Saas 7.2
A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2.
network
low complexity
workdo CWE-79
5.4
2024-09-20 CVE-2024-9031 Cross-site Scripting vulnerability in Workdo Crmgo Saas
A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2.
network
low complexity
workdo CWE-79
5.4
2024-09-20 CVE-2024-9043 Out-of-bounds Write vulnerability in Cellopoint Secure Email Gateway
Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process.
network
low complexity
cellopoint CWE-787
critical
9.8
2024-09-20 CVE-2024-8853 Unspecified vulnerability in Medialibs Webo-Facto
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function.
network
low complexity
medialibs
critical
9.8
2024-09-20 CVE-2024-9011 SQL Injection vulnerability in Code-Projects Crud Operation System 1.0
A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-09-20 CVE-2024-45806 Authorization Bypass Through User-Controlled Key vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-639
6.5
2024-09-20 CVE-2024-45807 Unspecified vulnerability in Envoyproxy Envoy 1.31.0/1.31.1
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy
7.5
2024-09-20 CVE-2024-45808 Improper Encoding or Escaping of Output vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-116
6.5
2024-09-20 CVE-2024-45809 NULL Pointer Dereference vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-476
7.5