Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-22 CVE-2021-38117 Command Injection vulnerability in Microfocus Imanager
Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
network
low complexity
microfocus CWE-77
critical
9.8
2024-11-22 CVE-2021-38135 Unspecified vulnerability in Microfocus Imanager
Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.
network
low complexity
microfocus
critical
9.8
2024-11-22 CVE-2023-24466 XXE vulnerability in Microfocus Imanager
Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.
network
low complexity
microfocus CWE-611
critical
9.8
2024-11-22 CVE-2023-24467 Command Injection vulnerability in Microfocus Imanager
Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.
network
low complexity
microfocus CWE-77
critical
9.8
2024-11-22 CVE-2024-52723 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.1041B20240224
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering.
network
low complexity
totolink CWE-78
critical
9.8
2024-11-22 CVE-2024-41779 IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition.
network
low complexity
CWE-367
critical
9.8
2024-11-21 CVE-2024-52053 Unspecified vulnerability in Wowza Streaming Engine
Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.
network
low complexity
wowza
critical
9.6
2024-11-21 CVE-2024-11592 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-21 CVE-2024-11591 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-21 CVE-2024-11590 SQL Injection vulnerability in 1000Projects Bookstore Management System 1.0
A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8