Latest CVE Feed
-
7.5
HIGHCVE-2024-49359
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allo... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
8.4
HIGHCVE-2024-47137
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.5
MEDIUMCVE-2024-47402
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-48932
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such ... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
8.4
HIGHCVE-2024-47404
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.4
HIGHCVE-2024-47797
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-10810
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the argument app_id leads to sql injection. It is possible to ... Read more
Affected Products : e-health_care_system- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-10809
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argument name/message leads to sql injection. The attack may b... Read more
Affected Products : e-health_care_system- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-10808
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the argument id leads to sql injection. The attack can be in... Read more
Affected Products : e-health_care_system- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10807
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripti... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
4.7
MEDIUMCVE-2024-10748
A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/desquared/kmmsharedmodule/db/RealmDB.java of the component Realm Database Han... Read more
Affected Products : what\'s_up- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10806
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cro... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10791
A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file /doctorAction.php. The manipulation of the argument Name leads to sql injection. The atta... Read more
Affected Products : hospital_appointment_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.1
HIGHCVE-2024-10749
A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to ... Read more
Affected Products : thinkadmin- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-10768
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of the argumen... Read more
Affected Products : online_shopping_portal- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51327
SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.... Read more
Affected Products : travel_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-51326
SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.... Read more
Affected Products : travel_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49760
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versio... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10766
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrest... Read more
Affected Products : free_exam_hall_seating_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.5
MEDIUMCVE-2024-49750
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector coul... Read more
Affected Products : snowflake_connector- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024