Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-1260 Unrestricted Upload of File with Dangerous Type vulnerability in Juanpao Jpshop 1.5.02
A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02.
network
low complexity
juanpao CWE-434
critical
9.8
2024-02-06 CVE-2024-1261 Unrestricted Upload of File with Dangerous Type vulnerability in Juanpao Jpshop 1.5.02
A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02.
network
low complexity
juanpao CWE-434
critical
9.8
2024-02-06 CVE-2024-24577 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libgit2
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.
network
low complexity
libgit2 CWE-119
critical
9.8
2024-02-06 CVE-2024-1259 Unspecified vulnerability in Juanpao Jpshop 1.5.02
A vulnerability was found in Juanpao JPShop up to 1.5.02.
network
low complexity
juanpao
critical
9.8
2024-02-06 CVE-2023-40545 Missing Authentication for Critical Function vulnerability in Pingidentity Pingfederate 11.3.0
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
network
low complexity
pingidentity CWE-306
critical
9.8
2024-02-06 CVE-2024-1252 Unspecified vulnerability in Tongda2000 Tongda Office Anywhere
A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9.
network
low complexity
tongda2000
critical
9.8
2024-02-06 CVE-2024-1251 Unspecified vulnerability in Tongda2000 Office Anywhere 2017 11.9
A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10.
network
low complexity
tongda2000
critical
9.8
2024-02-06 CVE-2024-24000 Unrestricted Upload of File with Dangerous Type vulnerability in Huaxiaerp Jsherp 3.3
jshERP v3.3 is vulnerable to Arbitrary File Upload.
network
low complexity
huaxiaerp CWE-434
critical
9.8
2024-02-06 CVE-2024-24013 SQL Injection vulnerability in Xxyopen Novel-Plus
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions.
network
low complexity
xxyopen CWE-89
critical
9.8
2024-02-06 CVE-2024-24015 SQL Injection vulnerability in Xxyopen Novel-Plus
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions.
network
low complexity
xxyopen CWE-89
critical
9.8