9.8

CVSS3.1

CVE-2024-48539 -

Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

9.8

CVSS3.1

CVE-2024-48538 -

Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

8.8

CVSS3.1

CVE-2024-48440 -

Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 8:35 p.m.

5.5

CVSS3.1

CVE-2024-48425 - assimp: SEGV in Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode

A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a …

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: June 10, 2025, 6:47 p.m.

7.8

CVSS3.1

CVE-2024-48423 - assimp: arbitrary code execution via CallbackToLogRedirector function

An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:40 a.m.

8

CVSS3.1

CVE-2024-45261 -

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's auth…

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2025, 5:54 p.m.

7.5

CVSS3.1

CVE-2024-48142 -

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 6:35 p.m.

6.2

CVSS3.1

CVE-2024-48426 - assimp: SEGV in SortByPTypeProcess::Execute

A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: May 28, 2025, 9:06 p.m.

9.1

CVSS3.1

CVE-2024-48145 -

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 28, 2024, 8:35 p.m.

9.1

CVSS3.1

CVE-2024-48143 -

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 6:35 p.m.
Total resulsts: 343944
Page 7635 of 34,395
Β« previous page Β» next page
Filters