Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-15 CVE-2024-44625 Path Traversal vulnerability in Gogs
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
network
low complexity
gogs CWE-22
8.8
2024-11-15 CVE-2024-50653 Unspecified vulnerability in Crmeb
CRMEB <=5.4.0 is vulnerable to Incorrect Access Control.
network
low complexity
crmeb
7.5
2024-11-15 CVE-2024-50654 Unspecified vulnerability in Pickmall Lilishop
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
network
low complexity
pickmall
7.5
2024-11-15 CVE-2024-52519 Insecure Storage of Sensitive Information vulnerability in Nextcloud Server 27.0.0/27.1.0/27.1.3
Nextcloud Server is a self hosted personal cloud system.
network
low complexity
nextcloud CWE-922
8.2
2024-11-15 CVE-2024-52525 Cleartext Storage of Sensitive Information vulnerability in Nextcloud Server
Nextcloud Server is a self hosted personal cloud system.
network
low complexity
nextcloud CWE-312
7.5
2024-11-15 CVE-2024-11245 SQL Injection vulnerability in Anisha Farmacia 1.0
A vulnerability, which was classified as critical, has been found in code-projects Farmacia 1.0.
network
low complexity
anisha CWE-89
7.5
2024-11-15 CVE-2024-41784 Path Traversal vulnerability in IBM Sterling Secure Proxy
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
7.5
2024-11-15 CVE-2024-52555 Unspecified vulnerability in Jetbrains Webstorm
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
local
low complexity
jetbrains
7.8
2024-11-15 CVE-2024-11241 SQL Injection vulnerability in Anisha JOB Recruitment 1.0
A vulnerability was found in code-projects Job Recruitment 1.0.
network
low complexity
anisha CWE-89
7.5
2024-11-15 CVE-2021-3742 Unspecified vulnerability in Chatwoot
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0.
network
low complexity
chatwoot
8.8