Latest CVE Feed
-
8.2
HIGHCVE-2024-39720
An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement poin... Read more
Affected Products : ollama- Published: Oct. 31, 2024
- Modified: May. 13, 2025
-
7.5
HIGHCVE-2024-39719
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, provid... Read more
Affected Products : ollama- Published: Oct. 31, 2024
- Modified: May. 13, 2025
-
7.5
HIGHCVE-2024-51066
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.... Read more
Affected Products : beauty_parlour_management_system- Published: Oct. 31, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2024-51065
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.... Read more
Affected Products : beauty_parlour_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2024-51064
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.... Read more
Affected Products : teachers_record_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.1
CRITICALCVE-2024-51063
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.... Read more
Affected Products : teachers_record_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.1
CRITICALCVE-2024-51060
Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.... Read more
- Published: Oct. 31, 2024
- Modified: May. 06, 2025
-
6.0
MEDIUMCVE-2024-50802
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.... Read more
Affected Products : abantecart- Published: Oct. 31, 2024
- Modified: Sep. 04, 2025
-
6.0
MEDIUMCVE-2024-50801
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.... Read more
Affected Products : abantecart- Published: Oct. 31, 2024
- Modified: Sep. 04, 2025
-
8.4
HIGHCVE-2024-48200
An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
9.9
CRITICALCVE-2024-42515
Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored ... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-39332
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.... Read more
Affected Products : webswing- Published: Oct. 31, 2024
- Modified: Jul. 10, 2025
-
6.7
MEDIUMCVE-2024-10573
An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The c... Read more
Affected Products : enterprise_linux- Published: Oct. 31, 2024
- Modified: Dec. 18, 2024
-
6.1
MEDIUMCVE-2023-52045
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.... Read more
Affected Products : elfinder- Published: Oct. 31, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2023-52044
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.... Read more
Affected Products : elfinder- Published: Oct. 31, 2024
- Modified: Apr. 17, 2025
-
9.9
CRITICALCVE-2024-51482
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.... Read more
Affected Products : zoneminder- Published: Oct. 31, 2024
- Modified: Nov. 05, 2024
-
0.0
NONECVE-2024-50356
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn'... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
6.3
MEDIUMCVE-2024-50347
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in ... Read more
Affected Products : laravel- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
3.7
LOWCVE-2024-7883
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first us... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
1.0
LOWCVE-2024-51481
Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, exposed to users with `import <nix/fetchurl.nix>`) were not executed in the macOS sandbox. Thus, these builders (which are running under th... Read more
- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024