Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-17 CVE-2024-6500 The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as 1.4.4 (for InPost PL).
network
low complexity
critical
10.0
2024-08-16 CVE-2024-43042 Improper Restriction of Excessive Authentication Attempts vulnerability in Pluck-Cms Pluck 4.7.18
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
network
low complexity
pluck-cms CWE-307
critical
9.8
2024-08-16 CVE-2022-33162 Unspecified vulnerability in IBM products
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user.
network
low complexity
ibm
critical
9.8
2024-08-16 CVE-2024-42638 Use of Hard-coded Credentials vulnerability in H3C Magic B1St Firmware 100R012
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
network
low complexity
h3c CWE-798
critical
9.8
2024-08-16 CVE-2024-42462 Improper Authentication vulnerability in Upkeeper Manager
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.
network
low complexity
upkeeper CWE-287
critical
9.8
2024-08-16 CVE-2024-42465 Improper Restriction of Excessive Authentication Attempts vulnerability in Upkeeper Manager
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
network
low complexity
upkeeper CWE-307
critical
9.8
2024-08-16 CVE-2024-42466 Improper Restriction of Excessive Authentication Attempts vulnerability in Upkeeper Manager
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
network
low complexity
upkeeper CWE-307
critical
9.8
2024-08-16 CVE-2024-7851 Unspecified vulnerability in Oretnom23 Yoga Class Registration System 1.0
A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical.
network
low complexity
oretnom23
critical
9.8
2024-08-15 CVE-2024-43366 Infinite Loop vulnerability in Matter-Labs Zkvyper
zkvyper is a Vyper compiler.
network
low complexity
matter-labs CWE-835
critical
9.1
2024-08-15 CVE-2024-7839 SQL Injection vulnerability in Angeljudesuarez Billing System 1.0
A vulnerability classified as critical has been found in itsourcecode Billing System 1.0.
network
low complexity
angeljudesuarez CWE-89
critical
9.8