Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-01-14 CVE-2024-48886 Unspecified vulnerability in Fortinet products
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
network
low complexity
fortinet
critical
9.8
2025-01-14 CVE-2024-54021 Interpretation Conflict vulnerability in Fortinet Fortios and Fortiproxy
An improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 allows attacker to execute unauthorized code or commands via crafted HTTP header.
network
low complexity
fortinet CWE-436
critical
9.8
2025-01-14 CVE-2024-55591 Unspecified vulnerability in Fortinet Fortios and Fortiproxy
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
network
low complexity
fortinet
critical
9.8
2025-01-14 CVE-2024-12919 Unspecified vulnerability in Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7.
network
low complexity
cozmoslabs
critical
9.8
2025-01-11 CVE-2024-12877 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'.
network
low complexity
CWE-502
critical
9.8
2025-01-10 CVE-2024-56511 Unspecified vulnerability in Dataease
DataEase is an open source data visualization analysis tool.
network
low complexity
dataease
critical
9.8
2025-01-10 CVE-2024-41787 IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition.
network
low complexity
CWE-367
critical
9.8
2025-01-09 CVE-2024-10215 The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4.
network
low complexity
CWE-639
critical
9.8
2025-01-09 CVE-2024-11642 The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the 'locate_template' function.
network
low complexity
CWE-22
critical
9.8
2025-01-09 CVE-2024-53704 Unspecified vulnerability in Sonicwall Sonicos
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
network
low complexity
sonicwall
critical
9.8