Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-06-07 CVE-2024-30163 SQL Injection vulnerability in Invisioncommunity
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries.
network
low complexity
invisioncommunity CWE-89
critical
9.8
2024-06-07 CVE-2024-36673 SQL Injection vulnerability in Pharmacy/Medical Store Point of Sale System Project Pharmacy/Medical Store Point of Sale System 1.0
Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php.
9.8
2024-06-07 CVE-2024-5733 Unspecified vulnerability in Online Discussion Forum Project Online Discussion Forum 1.0
A vulnerability was found in itsourcecode Online Discussion Forum 1.0.
network
low complexity
online-discussion-forum-project
critical
9.8
2024-06-07 CVE-2024-5732 Unspecified vulnerability in Clashforwindows Clash
A vulnerability was found in Clash up to 0.20.1 on Windows.
network
low complexity
clashforwindows
critical
9.8
2024-06-06 CVE-2024-24192 Out-of-bounds Read vulnerability in Robertdavidgraham Robdns 20151209
robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.
network
low complexity
robertdavidgraham CWE-125
critical
9.1
2024-06-06 CVE-2024-22074 Unspecified vulnerability in Dynamsoft Service
Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control.
network
low complexity
dynamsoft
critical
9.8
2024-06-06 CVE-2024-3166 Unspecified vulnerability in Mintplexlabs Anythingllm Desktop and Anythingllm Webapp
A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application.
network
low complexity
mintplexlabs
critical
9.6
2024-06-06 CVE-2024-3234 Unspecified vulnerability in Gaizhenbiao Chuanhuchatgpt
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component.
network
low complexity
gaizhenbiao
critical
9.8
2024-06-06 CVE-2024-3322 Unspecified vulnerability in Lollms web UI
A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5.
network
low complexity
lollms
critical
9.8
2024-06-06 CVE-2024-3408 Unspecified vulnerability in MAN D-Tale 3.10.0
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation.
network
low complexity
man
critical
9.8