Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-20 CVE-2024-11485 Unspecified vulnerability in Code4Berry Decoration Management System 1.0
A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0.
network
low complexity
code4berry
8.1
2024-11-20 CVE-2024-11487 SQL Injection vulnerability in Code4Berry Decoration Management System 1.0
A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical.
network
low complexity
code4berry CWE-89
8.8
2024-11-20 CVE-2024-51208 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul Boat Booking System 1.0
File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script via the Image Upload Mechanism parameter.
network
low complexity
phpgurukul CWE-434
7.2
2024-11-20 CVE-2024-10855 Authorization Bypass Through User-Controlled Key vulnerability in Sirv
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0.
network
low complexity
sirv CWE-639
8.1
2024-11-20 CVE-2024-10900 Missing Authorization vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6.
network
low complexity
metagauss CWE-862
8.1
2024-11-20 CVE-2024-44306 Classic Buffer Overflow vulnerability in Apple Macos
A buffer overflow issue was addressed with improved memory handling.
local
low complexity
apple CWE-120
7.8
2024-11-20 CVE-2024-44307 Classic Buffer Overflow vulnerability in Apple Macos
A buffer overflow issue was addressed with improved memory handling.
local
low complexity
apple CWE-120
7.8
2024-11-20 CVE-2024-44308 Unspecified vulnerability in Apple products
The issue was addressed with improved checks.
network
low complexity
apple
8.8
2024-11-19 CVE-2018-9456 Out-of-bounds Read vulnerability in Google Android
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check.
network
low complexity
google CWE-125
7.5
2024-11-19 CVE-2018-9466 Out-of-bounds Write vulnerability in Google Android
In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write.
network
low complexity
google CWE-787
8.8