Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-09 CVE-2024-25314 SQL Injection vulnerability in Hotel Management System Project Hotel Management System 1.0
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
network
low complexity
hotel-management-system-project CWE-89
critical
9.8
2024-02-09 CVE-2024-25315 SQL Injection vulnerability in Hotel Management System Project Hotel Management System 1.0
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
network
low complexity
hotel-management-system-project CWE-89
critical
9.8
2024-02-09 CVE-2024-25316 SQL Injection vulnerability in Hotel Management System Project Hotel Management System 1.0
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
network
low complexity
hotel-management-system-project CWE-89
critical
9.8
2024-02-09 CVE-2024-25678 Unspecified vulnerability in Litespeedtech Lsquic
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
network
low complexity
litespeedtech
critical
9.8
2024-02-09 CVE-2024-21762 Unspecified vulnerability in Fortinet Fortios
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
network
low complexity
fortinet
critical
9.8
2024-02-09 CVE-2024-25674 Unrestricted Upload of File with Dangerous Type vulnerability in Misp
An issue was discovered in MISP before 2.4.184.
network
low complexity
misp CWE-434
critical
9.8
2024-02-09 CVE-2024-25675 Unspecified vulnerability in Misp
An issue was discovered in MISP before 2.4.184.
network
low complexity
misp
critical
9.8
2024-02-09 CVE-2023-46350 SQL Injection vulnerability in Innovadeluxe Manufacturer or Supplier Alphabetical Search 2.0.4
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink, IdxrmanufacturerFunctions::getManufacturersLike and IdxrmanufacturerFunctions::getSuppliersLike.
network
low complexity
innovadeluxe CWE-89
critical
9.8
2024-02-09 CVE-2023-50026 SQL Injection vulnerability in Prestamonster Multi Accessories PRO 5.2.0
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().
network
low complexity
prestamonster CWE-89
critical
9.8
2024-02-09 CVE-2024-24308 SQL Injection vulnerability in Boostmyshop 1.1.9
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.
network
low complexity
boostmyshop CWE-89
critical
9.8