Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-02 CVE-2024-20520 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to execute arbitrary code as the root user.
network
low complexity
cisco CWE-787
critical
9.1
2024-10-02 CVE-2024-20521 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to execute arbitrary code as the root user.
network
low complexity
cisco CWE-787
critical
9.1
2024-10-02 CVE-2024-9429 SQL Injection vulnerability in Code-Projects Restaurant Reservation System 1.0
A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-02 CVE-2024-35293 An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.
network
low complexity
CWE-306
critical
9.1
2024-10-01 CVE-2024-45999 SQL Injection vulnerability in Magicbug Cloudlog
A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php.
network
low complexity
magicbug CWE-89
critical
9.8
2024-10-01 CVE-2024-47608 OS Command Injection vulnerability in Definetlynotai Logicytics
Logicytics is designed to harvest and collect data for forensic analysis.
network
low complexity
definetlynotai CWE-78
critical
9.8
2024-10-01 CVE-2023-3441 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4.
network
low complexity
gitlab
critical
9.1
2024-10-01 CVE-2024-9265 Unspecified vulnerability in Coderevolution Echo RSS Feed Post Generator
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6.
network
low complexity
coderevolution
critical
9.8
2024-10-01 CVE-2024-9289 Missing Authentication for Critical Function vulnerability in Redefiningtheweb Affiliate PRO
The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1.
network
low complexity
redefiningtheweb CWE-306
critical
9.8
2024-10-01 CVE-2024-9106 The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0.
network
low complexity
CWE-288
critical
9.8