Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-28990 Use of Hard-coded Credentials vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability.
network
low complexity
solarwinds CWE-798
critical
9.8
2024-09-12 CVE-2021-22533 Information Exposure Through Log Files vulnerability in Microfocus Edirectory
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
network
low complexity
microfocus CWE-532
critical
9.1
2024-09-12 CVE-2021-38132 Server-Side Request Forgery (SSRF) vulnerability in Microfocus Edirectory
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory.
network
low complexity
microfocus CWE-918
critical
9.8
2024-09-12 CVE-2024-29847 Deserialization of Untrusted Data vulnerability in Ivanti Endpoint Manager
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
network
low complexity
ivanti CWE-502
critical
9.8
2024-09-11 CVE-2024-8692 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tduckcloud Tduckpro
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3.
network
low complexity
tduckcloud CWE-640
critical
9.8
2024-09-11 CVE-2024-44466 Command Injection vulnerability in Comfast Cf-Xr11 Firmware 2.7.2
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4.
network
low complexity
comfast CWE-77
critical
9.8
2024-09-11 CVE-2024-27112 SQL Injection vulnerability in Soplanning
A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled.
network
low complexity
soplanning CWE-89
critical
9.8
2024-09-11 CVE-2024-27113 Authorization Bypass Through User-Controlled Key vulnerability in Soplanning
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled.
network
low complexity
soplanning CWE-639
critical
9.8
2024-09-11 CVE-2024-27114 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Soplanning
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool.
network
low complexity
soplanning CWE-367
critical
9.8
2024-09-11 CVE-2024-27115 Unrestricted Upload of File with Dangerous Type vulnerability in Soplanning
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool.
network
low complexity
soplanning CWE-434
critical
9.8