Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-07 CVE-2024-46446 Path Traversal vulnerability in Mecha-Cms Mecha 3.0.0
Mecha CMS 3.0.0 is vulnerable to Directory Traversal.
network
low complexity
mecha-cms CWE-22
critical
9.8
2024-10-07 CVE-2024-9570 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06B1
A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical.
network
low complexity
dlink CWE-120
8.8
2024-10-07 CVE-2024-9568 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06B1
A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8
2024-10-07 CVE-2024-9569 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06B1
A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical.
network
low complexity
dlink CWE-120
8.8
2024-10-07 CVE-2024-9571 Cross-site Scripting vulnerability in Soplanning
Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters.
network
low complexity
soplanning CWE-79
5.4
2024-10-07 CVE-2024-9572 Cross-site Scripting vulnerability in Soplanning
Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter.
network
low complexity
soplanning CWE-79
5.4
2024-10-07 CVE-2024-9573 SQL Injection vulnerability in Soplanning
SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.
network
low complexity
soplanning CWE-89
6.5
2024-10-07 CVE-2024-9574 SQL Injection vulnerability in Soplanning
SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
network
low complexity
soplanning CWE-89
6.5
2024-10-07 CVE-2024-9576 Unspecified vulnerability in Workbooth Project Workbooth 2.5
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.
local
low complexity
workbooth-project
7.8
2024-10-07 CVE-2024-9567 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06B1
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8