Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-29 CVE-2024-8294 Unrestricted Upload of File with Dangerous Type vulnerability in Feehi Feehicms
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1.
network
low complexity
feehi CWE-434
critical
9.8
2024-08-29 CVE-2024-45435 Unspecified vulnerability in Chartist
Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
network
low complexity
chartist
critical
9.8
2024-08-29 CVE-2024-7857 The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
critical
9.8
2024-08-29 CVE-2024-45233 Unspecified vulnerability in In2Code Powermail
An issue was discovered in powermail extension through 12.3.5 for TYPO3.
network
low complexity
in2code
critical
9.8
2024-08-28 CVE-2024-34195 Out-of-bounds Write vulnerability in Totolink A3002R Firmware 1.1.1B20200824
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow.
network
low complexity
totolink CWE-787
critical
9.8
2024-08-28 CVE-2024-44761 Path Traversal vulnerability in Gzequan EQ Enterprise Management System
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
network
low complexity
gzequan CWE-22
critical
9.8
2024-08-28 CVE-2023-26321 Path Traversal vulnerability in MI File Manager 1210567
A path traversal vulnerability exists in the Xiaomi File Manager application product(international version).
network
low complexity
mi CWE-22
critical
9.8
2024-08-28 CVE-2023-26322 Unspecified vulnerability in MI Getapps
A code execution vulnerability exists in the XiaomiGetApps application product.
network
low complexity
mi
critical
9.8
2024-08-28 CVE-2023-26323 Unspecified vulnerability in MI APP Market
A code execution vulnerability exists in the Xiaomi App market product.
network
low complexity
mi
critical
9.8
2024-08-28 CVE-2023-26324 Unspecified vulnerability in MI Getapps
A code execution vulnerability exists in the XiaomiGetApps application product.
network
low complexity
mi
critical
9.8