Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-13 CVE-2024-9916 OS Command Injection vulnerability in Usualtool Usualtoolcms 9.0
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9.
network
low complexity
usualtool CWE-78
critical
9.8
2024-10-12 CVE-2024-9047 The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php.
network
low complexity
CWE-22
critical
9.8
2024-10-11 CVE-2024-47331 SQL Injection vulnerability in Ninjateam Multi Step for Contact Form 7
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NinjaTeam Multi Step for Contact Form allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through 2.7.7.
network
low complexity
ninjateam CWE-89
critical
9.8
2024-10-11 CVE-2024-45402 Double Free vulnerability in Dena Picotls
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case.
network
low complexity
dena CWE-415
critical
9.8
2024-10-11 CVE-2024-47074 Deserialization of Untrusted Data vulnerability in Dataease
DataEase is an open source data visualization analysis tool.
network
low complexity
dataease CWE-502
critical
9.8
2024-10-11 CVE-2024-9822 Authentication Bypass Using an Alternate Path or Channel vulnerability in Pedalo Connector
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5.
network
low complexity
pedalo CWE-288
critical
9.8
2024-10-10 CVE-2024-47871 Missing Encryption of Sensitive Data vulnerability in Gradio Project Gradio
Gradio is an open-source Python package designed for quick prototyping.
network
low complexity
gradio-project CWE-311
critical
9.1
2024-10-10 CVE-2024-9818 SQL Injection vulnerability in Oretnom23 Online Veterinary Appointment System 1.0
A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0.
network
low complexity
oretnom23 CWE-89
critical
9.8
2024-10-10 CVE-2024-47167 Server-Side Request Forgery (SSRF) vulnerability in Gradio Project Gradio
Gradio is an open-source Python package designed for quick prototyping.
network
low complexity
gradio-project CWE-918
critical
9.8
2024-10-10 CVE-2024-9487 Improper Verification of Cryptographic Signature vulnerability in Github Enterprise Server
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance.
network
low complexity
github CWE-347
critical
9.1