Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-6202 Incorrect Authorization vulnerability in Haloservicesolutions Haloitsm
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability.
network
low complexity
haloservicesolutions CWE-863
critical
9.8
2024-08-06 CVE-2024-7500 Unrestricted Upload of File with Dangerous Type vulnerability in Angeljudesuarez Airline Reservation System 1.0
A vulnerability was found in itsourcecode Airline Reservation System 1.0.
network
low complexity
angeljudesuarez CWE-434
critical
9.8
2024-08-06 CVE-2024-7505 SQL Injection vulnerability in Rainniar Bike Delivery System 1.0
A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0.
network
low complexity
rainniar CWE-89
critical
9.8
2024-08-06 CVE-2024-5828 Expression Language Injection vulnerability in Hitachi Tuning Manager
Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.
network
low complexity
hitachi CWE-917
critical
9.8
2024-08-06 CVE-2024-7498 SQL Injection vulnerability in Angeljudesuarez Airline Reservation System 1.0
A vulnerability was found in itsourcecode Airline Reservation System 1.0.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2024-08-06 CVE-2024-7499 SQL Injection vulnerability in Angeljudesuarez Airline Reservation System 1.0
A vulnerability was found in itsourcecode Airline Reservation System 1.0.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2024-08-06 CVE-2024-7495 Unrestricted Upload of File with Dangerous Type vulnerability in Itsourcecode Laravel Accounting System 1.0
A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0.
network
low complexity
itsourcecode CWE-434
critical
9.8
2024-08-05 CVE-2024-7494 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0.
network
low complexity
oretnom23 CWE-89
critical
9.8
2024-08-05 CVE-2024-42008 Cross-site Scripting vulnerability in Roundcube Webmail
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
network
low complexity
roundcube CWE-79
critical
9.3
2024-08-05 CVE-2024-42009 Cross-site Scripting vulnerability in Roundcube Webmail
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
network
low complexity
roundcube CWE-79
critical
9.3