Latest CVE Feed
-
7.2
HIGHCVE-2024-10353
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls. It is possible to launch the attack remotely.... Read more
Affected Products : online_exam_system- Published: Oct. 25, 2024
- Modified: Oct. 30, 2024
-
9.0
HIGHCVE-2024-10351
A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads ... Read more
- Published: Oct. 25, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-10350
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection. The at... Read more
- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
4.6
MEDIUMCVE-2024-49762
Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are encrypted when usi... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
7.1
HIGHCVE-2024-49760
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versio... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
5.5
MEDIUMCVE-2024-49750
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector coul... Read more
Affected Products : snowflake_connector- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-49359
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allo... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-49358
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username e... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-49357
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `htt... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-41618
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated ... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-41617
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allo... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-10349
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected by this issue is the function delete_tenant of the file /ajax.php?action=delete_tenant. The manipulation of the argument id leads to s... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.4
MEDIUMCVE-2024-10348
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the component Manage Tenant Details. The manipulation of the ar... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-7763
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.... Read more
Affected Products : whatsup_gold- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.3
MEDIUMCVE-2024-48932
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such ... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-48931
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=<token>&files=<file_path>` is vulnerable to arbitra... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
6.2
MEDIUMCVE-2024-48426
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-48425
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, ... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-48424
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
8.4
HIGHCVE-2024-48423
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Nov. 21, 2024