Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-26 CVE-2024-9501 The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7.
network
low complexity
CWE-288
critical
9.8
2024-10-26 CVE-2024-9930 The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2.
network
low complexity
CWE-288
critical
9.8
2024-10-26 CVE-2024-9931 The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0.
network
low complexity
CWE-288
critical
9.8
2024-10-26 CVE-2024-9932 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0.
network
low complexity
CWE-434
critical
9.8
2024-10-25 CVE-2024-10386 Unspecified vulnerability in Rockwellautomation Thinmanager
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product.
network
low complexity
rockwellautomation
critical
9.8
2024-10-25 CVE-2024-48428 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Olivegroup Olivevle
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
network
low complexity
olivegroup CWE-640
critical
9.8
2024-10-25 CVE-2024-10381 Unspecified vulnerability in Matrixcomsec Cosec Vega Faxq Firmware
This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface.
network
low complexity
matrixcomsec
critical
9.8
2024-10-25 CVE-2024-10378 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability classified as critical has been found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-10-25 CVE-2024-10376 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-10-25 CVE-2024-10377 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8