Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-10658 SQL Injection vulnerability in Tongda2000 Office Anywhere 11.10
A vulnerability classified as critical was found in Tongda OA up to 11.10.
network
low complexity
tongda2000 CWE-89
critical
9.8
2024-11-01 CVE-2024-37277 Unspecified vulnerability in Strangerstudios Paid Memberships PRO
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
network
low complexity
strangerstudios
critical
9.8
2024-11-01 CVE-2024-37463 Unspecified vulnerability in Crmperks CRM Perks Forms
Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CRM Perks Forms: from n/a through 1.1.5.
network
low complexity
crmperks
critical
9.8
2024-11-01 CVE-2024-38748 Unspecified vulnerability in Theinnovs Eleforms
Access Control vulnerability in TheInnovs EleForms allows . This issue affects EleForms: from n/a through 2.9.9.9.
network
low complexity
theinnovs
critical
9.8
2024-11-01 CVE-2024-43253 Unspecified vulnerability in Zaytech Smart Online Order for Clover
Missing Authorization vulnerability in Zaytech Smart Online Order for Clover allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Smart Online Order for Clover: from n/a through 1.5.6.
network
low complexity
zaytech
critical
9.8
2024-11-01 CVE-2024-43323 Unspecified vulnerability in Wpdeveloper Reviewx
Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.
network
low complexity
wpdeveloper
critical
9.8
2024-11-01 CVE-2024-43341 Missing Authorization vulnerability in Cozythemes Hello Agency
Missing Authorization vulnerability in CozyThemes Hello Agency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hello Agency: from n/a through 1.0.5.
network
low complexity
cozythemes CWE-862
critical
9.8
2024-11-01 CVE-2024-43919 Missing Authorization vulnerability in Yarpp YET Another Related Posts Plugin
Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.
network
low complexity
yarpp CWE-862
critical
9.8
2024-11-01 CVE-2024-43923 Missing Authorization vulnerability in Arraytics WP Timetics
Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23.
network
low complexity
arraytics CWE-862
critical
9.8
2024-11-01 CVE-2024-43929 Missing Authorization vulnerability in Eyecix Jobsearch WP JOB Board
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.
network
low complexity
eyecix CWE-862
critical
9.8