Latest CVE Feed
-
5.3
MEDIUMCVE-2024-49358
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username e... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-49359
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allo... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
8.4
HIGHCVE-2024-47137
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.5
MEDIUMCVE-2024-47402
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-48932
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such ... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
8.4
HIGHCVE-2024-47404
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.4
HIGHCVE-2024-47797
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.... Read more
Affected Products : openharmony- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-10810
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the argument app_id leads to sql injection. It is possible to ... Read more
Affected Products : e-health_care_system- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-10809
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argument name/message leads to sql injection. The attack may b... Read more
Affected Products : e-health_care_system- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-10808
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the argument id leads to sql injection. The attack can be in... Read more
Affected Products : e-health_care_system- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10807
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripti... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
4.7
MEDIUMCVE-2024-10748
A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/desquared/kmmsharedmodule/db/RealmDB.java of the component Realm Database Han... Read more
Affected Products : what\'s_up- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10806
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cro... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10791
A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file /doctorAction.php. The manipulation of the argument Name leads to sql injection. The atta... Read more
Affected Products : hospital_appointment_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.1
HIGHCVE-2024-10749
A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to ... Read more
Affected Products : thinkadmin- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-10768
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of the argumen... Read more
Affected Products : online_shopping_portal- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51327
SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.... Read more
Affected Products : travel_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-51326
SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.... Read more
Affected Products : travel_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49760
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versio... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10766
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrest... Read more
Affected Products : free_exam_hall_seating_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024