Latest CVE Feed
-
9.8
CRITICALCVE-2024-41618
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated ... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-41617
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allo... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-10349
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected by this issue is the function delete_tenant of the file /ajax.php?action=delete_tenant. The manipulation of the argument id leads to s... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.4
MEDIUMCVE-2024-10348
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the component Manage Tenant Details. The manipulation of the ar... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-7763
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.... Read more
Affected Products : whatsup_gold- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.3
MEDIUMCVE-2024-48932
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such ... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-48931
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=<token>&files=<file_path>` is vulnerable to arbitra... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
6.2
MEDIUMCVE-2024-48426
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-48425
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, ... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-48424
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
8.4
HIGHCVE-2024-48423
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2024-48208
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.... Read more
Affected Products : pure-ftpd- Published: Oct. 24, 2024
- Modified: Sep. 04, 2025
-
9.1
CRITICALCVE-2024-47883
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or templates. This works: "opening... Read more
Affected Products : butterfly- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-47882
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the page... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
8.8
HIGHCVE-2024-47881
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to l... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
8.1
HIGHCVE-2024-47880
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An attac... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
8.8
HIGHCVE-2024-47879
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled expres... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Dec. 04, 2024
-
8.1
HIGHCVE-2024-47878
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without escaping. An attacker could le... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
8.8
HIGHCVE-2024-45263
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information lea... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
8.8
HIGHCVE-2024-45262
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execut... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024