Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-20 CVE-2024-9038 Unrestricted Upload of File with Dangerous Type vulnerability in Codezips Online Shopping Portal 1.0
A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0.
network
low complexity
codezips CWE-434
critical
9.8
2024-09-20 CVE-2024-9039 SQL Injection vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0.
network
low complexity
mayurik CWE-89
critical
9.8
2024-09-20 CVE-2024-9033 Cross-site Scripting vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic.
network
low complexity
mayurik CWE-79
5.4
2024-09-20 CVE-2024-9032 Path Traversal vulnerability in Oretnom23 Simple Forum/Discussion System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0.
network
low complexity
oretnom23 CWE-22
8.8
2024-09-20 CVE-2024-9030 Cross-site Scripting vulnerability in Workdo Crmgo Saas 7.2
A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2.
network
low complexity
workdo CWE-79
5.4
2024-09-20 CVE-2024-9031 Cross-site Scripting vulnerability in Workdo Crmgo Saas
A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2.
network
low complexity
workdo CWE-79
5.4
2024-09-20 CVE-2024-9043 Out-of-bounds Write vulnerability in Cellopoint Secure Email Gateway
Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process.
network
low complexity
cellopoint CWE-787
critical
9.8
2024-09-20 CVE-2024-8853 Unspecified vulnerability in Medialibs Webo-Facto
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function.
network
low complexity
medialibs
critical
9.8
2024-09-20 CVE-2024-9011 SQL Injection vulnerability in Code-Projects Crud Operation System 1.0
A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-09-20 CVE-2024-45806 Authorization Bypass Through User-Controlled Key vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-639
6.5