Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-11 CVE-2024-9822 Authentication Bypass Using an Alternate Path or Channel vulnerability in Pedalo Connector
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5.
network
low complexity
pedalo CWE-288
critical
9.8
2024-10-10 CVE-2024-47871 Missing Encryption of Sensitive Data vulnerability in Gradio Project Gradio
Gradio is an open-source Python package designed for quick prototyping.
network
low complexity
gradio-project CWE-311
critical
9.1
2024-10-10 CVE-2024-9818 SQL Injection vulnerability in Oretnom23 Online Veterinary Appointment System 1.0
A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0.
network
low complexity
oretnom23 CWE-89
critical
9.8
2024-10-10 CVE-2024-47167 Server-Side Request Forgery (SSRF) vulnerability in Gradio Project Gradio
Gradio is an open-source Python package designed for quick prototyping.
network
low complexity
gradio-project CWE-918
critical
9.8
2024-10-10 CVE-2024-9487 Improper Verification of Cryptographic Signature vulnerability in Github Enterprise Server
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance.
network
low complexity
github CWE-347
critical
9.1
2024-10-10 CVE-2024-9814 SQL Injection vulnerability in Codezips Pharmacy Management System 1.0
A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-10 CVE-2024-9811 SQL Injection vulnerability in Code-Projects Restaurant Reservation System 1.0
A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-10 CVE-2024-9812 SQL Injection vulnerability in Code-Projects Crud Operation System 1.0
A vulnerability classified as critical was found in code-projects Crud Operation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-10 CVE-2024-9813 SQL Injection vulnerability in Codezips Pharmacy Management System 1.0
A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-10 CVE-2024-47636 Deserialization of Untrusted Data vulnerability in Eyecix Jobsearch WP JOB Board
Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.
network
low complexity
eyecix CWE-502
critical
9.8