Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-18 CVE-2024-11311 Unrestricted Upload of File with Dangerous Type vulnerability in Trcore DVC
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files.
network
low complexity
trcore CWE-434
critical
9.8
2024-11-18 CVE-2024-11312 Unrestricted Upload of File with Dangerous Type vulnerability in Trcore DVC
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files.
network
low complexity
trcore CWE-434
critical
9.8
2024-11-18 CVE-2024-11313 Unrestricted Upload of File with Dangerous Type vulnerability in Trcore DVC
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files.
network
low complexity
trcore CWE-434
critical
9.8
2024-11-18 CVE-2024-11314 Unrestricted Upload of File with Dangerous Type vulnerability in Trcore DVC
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files.
network
low complexity
trcore CWE-434
critical
9.8
2024-11-18 CVE-2024-11315 Unrestricted Upload of File with Dangerous Type vulnerability in Trcore DVC
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files.
network
low complexity
trcore CWE-434
critical
9.8
2024-11-16 CVE-2024-8856 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21.
network
low complexity
CWE-434
critical
9.8
2024-11-15 CVE-2024-11256 SQL Injection vulnerability in 1000Projects Portfolio Management System MCA 1.0
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-15 CVE-2024-11257 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-15 CVE-2024-11258 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-15 CVE-2023-20036 A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. This vulnerability is due to improper input validation when uploading a Device Pack.
network
low complexity
CWE-78
critical
9.9