Latest CVE Feed
-
6.5
MEDIUMCVE-2024-48442
Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.8
HIGHCVE-2024-48441
Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.8
HIGHCVE-2024-48440
Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
9.8
CRITICALCVE-2024-46478
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.... Read more
Affected Products : htmldoc- Published: Oct. 24, 2024
- Modified: Jun. 24, 2025
-
5.9
MEDIUMCVE-2024-38314
IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.... Read more
Affected Products : maximo_application_suite- Published: Oct. 24, 2024
- Modified: Jul. 08, 2025
-
7.2
HIGHCVE-2024-10338
A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/home.php. The manipulation of the argument view/view1 leads to sql injectio... Read more
Affected Products : clothes_recommendation_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
7.2
HIGHCVE-2024-10337
A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is an unknown function of the file /admin/home.php?con=add. The manipulation of the argument cat/subcat/ t1/t2/text leads to sql injection.... Read more
Affected Products : clothes_recommendation_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
8.6
HIGHCVE-2024-10313
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
7.5
HIGHCVE-2024-10295
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauth... Read more
Affected Products : 3scale_api_management- Published: Oct. 24, 2024
- Modified: Jun. 18, 2025
-
6.9
MEDIUMCVE-2024-9692
VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
9.3
CRITICALCVE-2024-48548
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a valid serial number... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.4
HIGHCVE-2024-48547
Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.4
HIGHCVE-2024-48546
Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.4
HIGHCVE-2024-48545
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.4
HIGHCVE-2024-48544
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.4
HIGHCVE-2024-48542
Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.4
HIGHCVE-2024-48541
Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
6.2
MEDIUMCVE-2024-48540
Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
9.8
CRITICALCVE-2024-48539
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
9.3
CRITICALCVE-2024-44206
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. A user may be able to bypass some web content restrictions... Read more
- Published: Oct. 24, 2024
- Modified: Nov. 21, 2024