Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-11099 SQL Injection vulnerability in Anisha JOB Recruitment 1.0
A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical.
network
low complexity
anisha CWE-89
critical
9.8
2024-11-12 CVE-2024-49393 Improper Verification of Cryptographic Signature vulnerability in multiple products
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
network
high complexity
neomutt mutt redhat CWE-347
5.9
2024-11-12 CVE-2024-8881 OS Command Injection vulnerability in Zyxel products
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
low complexity
zyxel CWE-78
6.8
2024-11-12 CVE-2024-8882 Classic Buffer Overflow vulnerability in Zyxel products
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.
low complexity
zyxel CWE-120
4.5
2024-11-12 CVE-2024-11096 SQL Injection vulnerability in Code-Projects Task Manager 1.0
A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0.
network
low complexity
code-projects CWE-89
6.5
2024-11-12 CVE-2024-47595 Unspecified vulnerability in SAP Host Agent 7.22
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access.
local
low complexity
sap
7.1
2024-11-12 CVE-2024-11079 A flaw was found in Ansible-Core.
network
high complexity
CWE-20
5.5
2024-11-11 CVE-2024-11078 Cross-site Scripting vulnerability in Anisha JOB Recruitment 1.0
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic.
network
low complexity
anisha CWE-79
5.4
2024-11-11 CVE-2024-51484 Cross-Site Request Forgery (CSRF) vulnerability in Ampache 7.0.0
Ampache is a web based audio/video streaming application and file manager.
network
low complexity
ampache CWE-352
8.1
2024-11-11 CVE-2024-51485 Cross-Site Request Forgery (CSRF) vulnerability in Ampache 7.0.0
Ampache is a web based audio/video streaming application and file manager.
network
low complexity
ampache CWE-352
8.1