Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-23 CVE-2024-47222 Server-Side Request Forgery (SSRF) vulnerability in Myoffice MY Office SDK
New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.
network
low complexity
myoffice CWE-918
critical
9.8
2024-09-23 CVE-2024-0001 Insecure Default Initialization of Resource vulnerability in Purestorage Purity//Fa
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
network
low complexity
purestorage CWE-1188
critical
9.8
2024-09-23 CVE-2024-0002 Unspecified vulnerability in Purestorage Purity//Fa
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
network
low complexity
purestorage
critical
9.8
2024-09-23 CVE-2024-46997 Unspecified vulnerability in Dataease
DataEase is an open source data visualization analysis tool.
network
low complexity
dataease
critical
9.8
2024-09-23 CVE-2024-9094 SQL Injection vulnerability in Code-Projects Blood Bank System 1.0
A vulnerability classified as critical was found in code-projects Blood Bank System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-09-23 CVE-2024-9090 SQL Injection vulnerability in Mayurik Modern Loan Management System 1.0
A vulnerability was found in SourceCodester Modern Loan Management System 1.0.
network
low complexity
mayurik CWE-89
critical
9.8
2024-09-23 CVE-2024-9091 SQL Injection vulnerability in Code-Projects Student Record System 1.0
A vulnerability was found in code-projects Student Record System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-09-22 CVE-2024-9087 SQL Injection vulnerability in Vehicle Management Project Vehicle Management 1.0
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0.
network
low complexity
vehicle-management-project CWE-89
critical
9.8
2024-09-22 CVE-2024-9088 Classic Buffer Overflow vulnerability in Razormist Telecom Billing Management System 1.0
A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical.
network
low complexity
razormist CWE-120
critical
9.8
2024-09-22 CVE-2024-9086 SQL Injection vulnerability in Code-Projects Restaurant Reservation System 1.0
A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8