Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-01-20 CVE-2025-0579 A vulnerability was found in Shiprocket Module 3/4 on OpenCart.
network
low complexity
CWE-74
7.3
2025-01-20 CVE-2025-0586 The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.
network
low complexity
CWE-502
7.2
2025-01-19 CVE-2024-41742 IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations.
network
low complexity
CWE-770
7.5
2025-01-19 CVE-2024-41743 IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.
network
low complexity
CWE-770
7.5
2025-01-19 CVE-2025-0566 A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13.
network
low complexity
CWE-121
8.8
2025-01-19 CVE-2025-0565 A vulnerability was found in ZZCMS 2023.
network
low complexity
CWE-74
7.3
2025-01-19 CVE-2025-0564 A vulnerability was found in code-projects Fantasy-Cricket 1.0.
network
low complexity
CWE-74
7.3
2025-01-18 CVE-2024-45662 IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due to improper allocation of resources.
network
low complexity
CWE-770
7.5
2025-01-18 CVE-2024-47113 IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6.
network
low complexity
CWE-91
8.1
2025-01-18 CVE-2024-13184 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
7.5