Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-23049 Command Injection vulnerability in B3Log Symphony
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
network
low complexity
b3log CWE-77
critical
9.8
2024-02-05 CVE-2023-6933 Deserialization of Untrusted Data vulnerability in Wpengine Better Search Replace
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input.
network
low complexity
wpengine CWE-502
critical
9.8
2024-02-05 CVE-2023-6989 Path Traversal vulnerability in Getshieldsecurity Shield Security
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter.
network
low complexity
getshieldsecurity CWE-22
critical
9.8
2024-02-05 CVE-2023-51951 SQL Injection vulnerability in Stock Management System Project Stock Management System 1.0
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.
network
low complexity
stock-management-system-project CWE-89
critical
9.8
2024-02-05 CVE-2024-24543 Out-of-bounds Write vulnerability in Tenda AC9 Firmware 15.03.06.42Multi
Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.
network
low complexity
tenda CWE-787
critical
9.8
2024-02-05 CVE-2024-0323 Unspecified vulnerability in Br-Automation Automation Runtime
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1.
network
low complexity
br-automation
critical
9.8
2024-02-05 CVE-2024-23054 Uncontrolled Search Path Element vulnerability in Plone Docker Official Image 5.2.13
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
network
low complexity
plone CWE-427
critical
9.8
2024-02-05 CVE-2023-52138 Link Following vulnerability in Mate-Desktop Engrampa
Engrampa is an archive manager for the MATE environment.
network
low complexity
mate-desktop CWE-59
critical
9.6
2024-02-05 CVE-2024-23108 Unspecified vulnerability in Fortinet Fortisiem
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.
network
low complexity
fortinet
critical
9.8
2024-02-05 CVE-2024-23109 OS Command Injection vulnerability in Fortinet Fortisiem
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.
network
low complexity
fortinet CWE-78
critical
9.8