Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-22 CVE-2024-8081 SQL Injection vulnerability in Kevinwong Payroll Management System 1.0
A vulnerability classified as critical was found in itsourcecode Payroll Management System 1.0.
network
low complexity
kevinwong CWE-89
critical
9.8
2024-08-22 CVE-2024-8078 Classic Buffer Overflow vulnerability in Totolink T8 Firmware 4.1.5Cu.862B20230228
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228.
network
low complexity
totolink CWE-120
critical
9.8
2024-08-22 CVE-2024-8079 Classic Buffer Overflow vulnerability in Totolink T8 Firmware 4.1.5Cu.862B20230228
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228.
network
low complexity
totolink CWE-120
critical
9.8
2024-08-22 CVE-2024-8080 SQL Injection vulnerability in Online Health Care System Project Online Health Care System 1.0
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0.
network
low complexity
online-health-care-system-project CWE-89
critical
9.8
2024-08-22 CVE-2024-8075 OS Command Injection vulnerability in Totolink T8 Firmware 4.1.5Cu.862B20230228
A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical.
network
low complexity
totolink CWE-78
critical
9.8
2024-08-22 CVE-2024-8076 Classic Buffer Overflow vulnerability in Totolink T8 Firmware 4.1.5Cu.862B20230228
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical.
network
low complexity
totolink CWE-120
critical
9.8
2024-08-22 CVE-2024-8077 OS Command Injection vulnerability in Totolink T8 Firmware 4.1.5Cu.862B20230228
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228.
network
low complexity
totolink CWE-78
critical
9.8
2024-08-21 CVE-2024-28987 Unspecified vulnerability in Solarwinds web Help Desk
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
network
low complexity
solarwinds
critical
9.1
2024-08-21 CVE-2024-7971 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.
network
low complexity
google microsoft CWE-843
critical
9.6
2024-08-21 CVE-2024-42777 Unrestricted Upload of File with Dangerous Type vulnerability in Lopalopa Music Management System 1.0
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
network
low complexity
lopalopa CWE-434
critical
9.8