Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-05 CVE-2024-10808 SQL Injection vulnerability in Anisha E-Health Care System 1.0
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical.
network
low complexity
anisha CWE-89
7.5
2024-11-05 CVE-2024-10809 SQL Injection vulnerability in Anisha E-Health Care System 1.0
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical.
network
low complexity
anisha CWE-89
7.5
2024-11-05 CVE-2024-10810 SQL Injection vulnerability in Anisha E-Health Care System 1.0
A vulnerability was found in code-projects E-Health Care System 1.0.
network
low complexity
anisha CWE-89
7.5
2024-11-05 CVE-2024-31998 Cross-Site Request Forgery (CSRF) vulnerability in Combodo Itop
Combodo iTop is a simple, web based IT Service Management tool.
network
low complexity
combodo CWE-352
8.8
2024-11-04 CVE-2024-10805 SQL Injection vulnerability in Anisha University Event Management System 1.0
A vulnerability was found in code-projects University Event Management System 1.0.
network
low complexity
anisha CWE-89
8.8
2024-11-04 CVE-2024-51127 Unspecified vulnerability in Redhat Hornetq
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
local
low complexity
redhat
7.1
2024-11-04 CVE-2024-51326 SQL Injection vulnerability in Projectworlds Travel Management System 1.0
SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.
network
low complexity
projectworlds CWE-89
7.5
2024-11-04 CVE-2024-51329 Code Injection vulnerability in Idrsdev Agile-Board 1.0
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.
network
low complexity
idrsdev CWE-94
8.8
2024-11-04 CVE-2024-48809 Allocation of Resources Without Limits or Throttling vulnerability in Aetherproject Onos-A1T and Sdran-In-A-Box
An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifically the DeleteWatcher function.
network
low complexity
aetherproject CWE-770
7.5
2024-11-04 CVE-2024-51626 SQL Injection vulnerability in Mansurahamed Woocommerce Quote Calculator
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.
network
low complexity
mansurahamed CWE-89
8.8