Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-19 CVE-2024-47088 Improper Restriction of Excessive Authentication Attempts vulnerability in Apexsoftcell LD DP Back Office and LD GEO
This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login.
network
low complexity
apexsoftcell CWE-307
critical
9.8
2024-09-18 CVE-2024-46986 Path Traversal vulnerability in Tuzitio Camaleon CMS
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails.
network
low complexity
tuzitio CWE-22
critical
9.9
2024-09-18 CVE-2024-34026 Out-of-bounds Write vulnerability in Openplcproject Openplc V3 Firmware 20240404
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88.
network
low complexity
openplcproject CWE-787
critical
9.8
2024-09-18 CVE-2024-5960 Unprotected Storage of Credentials vulnerability in Elizsoftware Panel
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.
network
low complexity
elizsoftware CWE-256
critical
9.8
2024-09-18 CVE-2024-8892 Unspecified vulnerability in Circutor Tcp2Rs+ Firmware 1.3B
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use.
network
low complexity
circutor
critical
9.1
2024-09-18 CVE-2024-8889 Unspecified vulnerability in Circutor Tcp2Rs+ Firmware 1.3B
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use.
network
low complexity
circutor
critical
9.1
2024-09-17 CVE-2024-43976 SQL Injection vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 6.9.7.
network
low complexity
superstorefinder CWE-89
critical
9.8
2024-09-17 CVE-2024-43978 SQL Injection vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a before 6.9.8.
network
low complexity
superstorefinder CWE-89
critical
9.8
2024-09-17 CVE-2024-44004 SQL Injection vulnerability in Wptaskforce Track & Trace
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTaskForce WPCargo Track & Trace allows SQL Injection.This issue affects WPCargo Track & Trace: from n/a through 7.0.6.
network
low complexity
wptaskforce CWE-89
critical
9.8
2024-09-17 CVE-2024-8957 OS Command Injection vulnerability in Ptzoptics Pt30X-Ndi-Xx-G2 Firmware and Pt30X-Sdi Firmware
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue.
network
low complexity
ptzoptics CWE-78
critical
9.8