Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-17 CVE-2024-8944 SQL Injection vulnerability in Fabianros Hospital Management System 1.0
A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0.
network
low complexity
fabianros CWE-89
critical
9.8
2024-09-17 CVE-2024-8945 SQL Injection vulnerability in Fairsketch Rise Ultimate Project Manager 3.7.0
A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical.
network
low complexity
fairsketch CWE-89
8.8
2024-09-17 CVE-2021-27916 Path Traversal vulnerability in Acquia Mautic
Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion.
network
low complexity
acquia CWE-22
8.1
2024-09-17 CVE-2024-7788 Improper Verification of Cryptographic Signature vulnerability in Libreoffice
Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.
local
low complexity
libreoffice CWE-347
7.8
2024-09-17 CVE-2021-27915 Cross-site Scripting vulnerability in Acquia Mautic
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permissions. This could lead to the user having elevated access to the system.
network
low complexity
acquia CWE-79
critical
9.0
2024-09-17 CVE-2024-38860 Cross-site Scripting vulnerability in Checkmk 2.2.0/2.3.0
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
network
low complexity
checkmk CWE-79
6.1
2024-09-17 CVE-2024-47047 Authorization Bypass Through User-Controlled Key vulnerability in In2Code Powermail
An issue was discovered in the powermail extension through 12.4.0 for TYPO3.
network
low complexity
in2code CWE-639
7.5
2024-09-17 CVE-2024-47049 Server-Side Request Forgery (SSRF) vulnerability in Czim File-Handling
The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.
network
low complexity
czim CWE-918
8.2
2024-09-17 CVE-2024-8897 Open Redirect vulnerability in Mozilla Firefox
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents.
network
low complexity
mozilla CWE-601
6.1
2024-09-17 CVE-2024-8761 Open Redirect vulnerability in Wp-Unit Share This Image
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03.
network
low complexity
wp-unit CWE-601
6.1