Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-20 CVE-2024-9038 Unrestricted Upload of File with Dangerous Type vulnerability in Codezips Online Shopping Portal 1.0
A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0.
network
low complexity
codezips CWE-434
critical
9.8
2024-09-20 CVE-2024-9039 SQL Injection vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0.
network
low complexity
mayurik CWE-89
critical
9.8
2024-09-20 CVE-2024-9043 Out-of-bounds Write vulnerability in Cellopoint Secure Email Gateway
Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process.
network
low complexity
cellopoint CWE-787
critical
9.8
2024-09-20 CVE-2024-8853 Unspecified vulnerability in Medialibs Webo-Facto
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function.
network
low complexity
medialibs
critical
9.8
2024-09-20 CVE-2024-9011 SQL Injection vulnerability in Code-Projects Crud Operation System 1.0
A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-09-20 CVE-2024-9009 SQL Injection vulnerability in Fabianros Online Quiz Site 1.0
A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0.
network
low complexity
fabianros CWE-89
critical
9.8
2024-09-19 CVE-2023-27584 Use of Hard-coded Credentials vulnerability in Linuxfoundation Dragonfly
Dragonfly is an open source P2P-based file distribution and image acceleration system.
network
low complexity
linuxfoundation CWE-798
critical
9.8
2024-09-19 CVE-2024-46983 Unspecified vulnerability in Antfin Sofa-Hessian
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd.
network
low complexity
antfin
critical
9.8
2024-09-19 CVE-2024-46984 XXE vulnerability in Gematik Reference Validator
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards.
network
low complexity
gematik CWE-611
critical
9.8
2024-09-19 CVE-2024-9008 SQL Injection vulnerability in Best Online News Portal Project Best Online News Portal 1.0
A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0.
network
low complexity
best-online-news-portal-project CWE-89
critical
9.8