Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-45321 Download of Code Without Integrity Check vulnerability in App::Cpanminus Project App::Cpanminus
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
network
low complexity
app CWE-494
critical
9.8
2024-08-26 CVE-2024-42913 SQL Injection vulnerability in Ruoyi 4.7.9
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
network
low complexity
ruoyi CWE-89
critical
9.8
2024-08-26 CVE-2024-45265 SQL Injection vulnerability in Skyss Arfa-Cms
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
network
low complexity
skyss CWE-89
critical
9.8
2024-08-26 CVE-2024-41444 SQL Injection vulnerability in Seacms 12.9
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
network
low complexity
seacms CWE-89
critical
9.8
2024-08-26 CVE-2024-41285 Out-of-bounds Write vulnerability in Fastcom Fw300R Firmware 1.3.13Build141023Rel.61347N
A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.
network
low complexity
fastcom CWE-787
critical
9.8
2024-08-26 CVE-2024-44549 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
network
low complexity
tenda CWE-787
critical
9.8
2024-08-26 CVE-2024-44550 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
network
low complexity
tenda CWE-787
critical
9.8
2024-08-26 CVE-2024-44551 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
network
low complexity
tenda CWE-787
critical
9.8
2024-08-26 CVE-2024-44552 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
network
low complexity
tenda CWE-787
critical
9.8
2024-08-26 CVE-2024-44553 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
network
low complexity
tenda CWE-787
critical
9.8