Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-20 CVE-2024-7937 SQL Injection vulnerability in Project Expense Monitoring System Project Expense Monitoring System 1.0
A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0.
network
low complexity
project-expense-monitoring-system-project CWE-89
critical
9.8
2024-08-20 CVE-2024-7936 SQL Injection vulnerability in Project Expense Monitoring System Project Expense Monitoring System 1.0
A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0.
network
low complexity
project-expense-monitoring-system-project CWE-89
critical
9.8
2024-08-19 CVE-2024-7933 SQL Injection vulnerability in Project Expense Monitoring System Project Expense Monitoring System 1.0
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0.
network
low complexity
project-expense-monitoring-system-project CWE-89
critical
9.8
2024-08-19 CVE-2024-7934 SQL Injection vulnerability in Project Expense Monitoring System Project Expense Monitoring System 1.0
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0.
network
low complexity
project-expense-monitoring-system-project CWE-89
critical
9.8
2024-08-19 CVE-2024-7935 SQL Injection vulnerability in Project Expense Monitoring System Project Expense Monitoring System 1.0
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0.
network
low complexity
project-expense-monitoring-system-project CWE-89
critical
9.8
2024-08-19 CVE-2024-42812 Classic Buffer Overflow vulnerability in Dlink Dir-860L Firmware 2.0.3
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi.
network
low complexity
dlink CWE-120
critical
9.8
2024-08-19 CVE-2024-43242 Deserialization of Untrusted Data vulnerability in Wpindeed Ultimate Membership PRO
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6.
network
low complexity
wpindeed CWE-502
critical
10.0
2024-08-19 CVE-2024-43248 Path Traversal vulnerability in Bitapps BIT Form
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.
network
low complexity
bitapps CWE-22
critical
9.1
2024-08-19 CVE-2024-42658 Unspecified vulnerability in Nepstech Ntpl-Xpon1Gfevn Firmware 1.0
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
network
low complexity
nepstech
critical
9.8
2024-08-19 CVE-2024-43240 Unspecified vulnerability in Wpindeed Ultimate Membership PRO
Improper Privilege Management vulnerability in azzaroco Ultimate Membership Pro allows Privilege Escalation.This issue affects Ultimate Membership Pro: from n/a through 12.6.
network
low complexity
wpindeed
critical
9.8