Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-26 CVE-2024-11745 Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.09
A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical.
network
low complexity
tenda CWE-787
critical
9.8
2024-11-26 CVE-2024-49035 Unspecified vulnerability in Microsoft Partner Center
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
network
low complexity
microsoft
critical
9.8
2024-11-26 CVE-2024-49038 Unspecified vulnerability in Microsoft Copilot Studio
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
network
low complexity
microsoft
critical
9.6
2024-11-26 CVE-2024-49052 Unspecified vulnerability in Microsoft Azure Functions
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
microsoft
critical
9.8
2024-11-26 CVE-2024-11680 Incorrect Authorization vulnerability in Projectsend
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability.
network
low complexity
projectsend CWE-863
critical
9.8
2024-11-26 CVE-2017-11076 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
network
low complexity
qualcomm CWE-119
critical
9.8
2024-11-26 CVE-2017-17772 Out-of-bounds Read vulnerability in Qualcomm products
In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
network
low complexity
qualcomm CWE-125
critical
9.8
2024-11-25 CVE-2024-11663 SQL Injection vulnerability in Codezips E-Commerce Site 1.0
A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-11-25 CVE-2024-11664 Unspecified vulnerability in Enms
A vulnerability, which was classified as critical, has been found in eNMS up to 4.2.
network
low complexity
enms
critical
9.8
2024-11-25 CVE-2024-11661 Unrestricted Upload of File with Dangerous Type vulnerability in Codezips Free Exam Hall Seating Management System 1.0
A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0.
network
low complexity
codezips CWE-434
critical
9.8