Latest CVE Feed
-
8.7
HIGHCVE-2024-10387
CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.... Read more
Affected Products : thinmanager- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-10386
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.... Read more
Affected Products : thinmanager- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
5.3
MEDIUMCVE-2022-30361
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s),... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
6.4
MEDIUMCVE-2022-30360
OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
5.4
MEDIUMCVE-2022-30359
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2022-30358
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2022-30357
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2022-30356
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48581
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.... Read more
Affected Products : best_courier_management_system- Published: Oct. 25, 2024
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2024-48580
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.... Read more
Affected Products : best_courier_management_system- Published: Oct. 25, 2024
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2024-48579
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-48204
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
5.3
MEDIUMCVE-2023-26248
The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the conte... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2022-30355
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
7.5
HIGHCVE-2022-30354
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2024-49757
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Regi... Read more
Affected Products : zitadel- Published: Oct. 25, 2024
- Modified: Aug. 26, 2025
-
9.8
CRITICALCVE-2024-48428
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.... Read more
Affected Products : olivevle- Published: Oct. 25, 2024
- Modified: Mar. 19, 2025
-
9.1
CRITICALCVE-2024-49753
Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests t... Read more
Affected Products : zitadel- Published: Oct. 25, 2024
- Modified: Aug. 26, 2025
-
7.7
HIGHCVE-2024-49381
Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to informati... Read more
Affected Products : plenti- Published: Oct. 25, 2024
- Modified: Nov. 14, 2024
-
8.9
HIGHCVE-2024-49380
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote ... Read more
Affected Products : plenti- Published: Oct. 25, 2024
- Modified: May. 06, 2025