Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-11 CVE-2024-11068 Incorrect Use of Privileged APIs vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.
network
low complexity
dlink CWE-648
critical
9.8
2024-11-11 CVE-2024-11016 SQL Injection vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
network
low complexity
vice CWE-89
critical
9.8
2024-11-11 CVE-2024-11018 Unrestricted Upload of File with Dangerous Type vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
network
low complexity
vice CWE-434
critical
9.8
2024-11-11 CVE-2024-51793 Unrestricted Upload of File with Dangerous Type vulnerability in Webfulcreations Computer Repair Shop
Unrestricted Upload of File with Dangerous Type vulnerability in Webful Creations Computer Repair Shop allows Upload a Web Shell to a Web Server.This issue affects Computer Repair Shop: from n/a through 3.8115.
network
low complexity
webfulcreations CWE-434
critical
9.8
2024-11-10 CVE-2024-46613 Integer Overflow or Wraparound vulnerability in Weechat
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list.
network
low complexity
weechat CWE-190
critical
9.8
2024-11-10 CVE-2024-11057 SQL Injection vulnerability in Codezips Hospital Appointment System 1.0
A vulnerability has been found in Codezips Hospital Appointment System 1.0 and classified as critical.
network
low complexity
codezips CWE-89
critical
9.8
2024-11-10 CVE-2024-11055 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-10 CVE-2024-11054 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Simple Music Cloud Community System 1.0
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0.
network
low complexity
oretnom23 CWE-434
critical
9.8
2024-11-10 CVE-2024-11047 Stack-based Buffer Overflow vulnerability in Dlink Di-8003 Firmware 16.07.16A1
A vulnerability was found in D-Link DI-8003 16.07.16A1.
network
low complexity
dlink CWE-121
critical
9.8
2024-11-10 CVE-2024-11048 Stack-based Buffer Overflow vulnerability in Dlink Di-8003 Firmware 16.07.16A1
A vulnerability was found in D-Link DI-8003 16.07.16A1.
network
low complexity
dlink CWE-121
critical
9.8