Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-10 CVE-2024-54093 Heap-based Buffer Overflow vulnerability in Siemens Solid Edge Se2024 224.0
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5).
local
low complexity
siemens CWE-122
7.8
2024-12-10 CVE-2024-54094 Heap-based Buffer Overflow vulnerability in Siemens Solid Edge Se2024 224.0
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5).
local
low complexity
siemens CWE-122
7.8
2024-12-10 CVE-2024-54095 Integer Underflow (Wrap or Wraparound) vulnerability in Siemens Solid Edge Se2024 224.0
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 10).
local
low complexity
siemens CWE-191
7.8
2024-12-10 CVE-2024-47977 Unspecified vulnerability in Dell Avamar Server
Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
network
low complexity
dell
8.8
2024-12-10 CVE-2024-52538 Unspecified vulnerability in Dell Avamar Server
Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
network
low complexity
dell
8.8
2024-12-10 CVE-2023-6947 Path Traversal vulnerability in Fooplugins Foogallery 2.4.15
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26.
network
low complexity
fooplugins CWE-22
7.7
2024-12-10 CVE-2024-11205 The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1.
network
low complexity
CWE-862
8.5
2024-12-09 CVE-2024-54922 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54930 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54933 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
network
low complexity
lopalopa CWE-89
7.2