Latest CVE Feed
-
7.5
HIGHCVE-2024-49359
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allo... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-49358
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username e... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-49357
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `htt... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-41618
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated ... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-41617
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allo... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-10349
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected by this issue is the function delete_tenant of the file /ajax.php?action=delete_tenant. The manipulation of the argument id leads to s... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.4
MEDIUMCVE-2024-10348
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=tenants of the component Manage Tenant Details. The manipulation of the ar... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-7763
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.... Read more
Affected Products : whatsup_gold- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
5.3
MEDIUMCVE-2024-48932
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such ... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-48931
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=<token>&files=<file_path>` is vulnerable to arbitra... Read more
Affected Products : zimaos- Published: Oct. 24, 2024
- Modified: Nov. 06, 2024
-
6.2
MEDIUMCVE-2024-48426
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-48425
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, ... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-48424
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
8.4
HIGHCVE-2024-48423
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2024-48208
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.... Read more
Affected Products : pure-ftpd- Published: Oct. 24, 2024
- Modified: Sep. 04, 2025
-
9.1
CRITICALCVE-2024-47883
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or templates. This works: "opening... Read more
Affected Products : butterfly- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-47882
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the page... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
8.8
HIGHCVE-2024-47881
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to l... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
8.1
HIGHCVE-2024-47880
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An attac... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
8.8
HIGHCVE-2024-47879
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled expres... Read more
Affected Products : openrefine- Published: Oct. 24, 2024
- Modified: Dec. 04, 2024