6.2

CVSS3.1

CVE-2024-48426 - assimp: SEGV in SortByPTypeProcess::Execute

A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: May 28, 2025, 9:06 p.m.

9.1

CVSS3.1

CVE-2024-48145 -

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 28, 2024, 8:35 p.m.

9.1

CVSS3.1

CVE-2024-48143 -

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 6:35 p.m.

7.5

CVSS3.1

CVE-2024-48139 -

A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 7:35 p.m.

7.5

CVSS3.1

CVE-2024-48140 -

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 7:35 p.m.

9.8

CVSS3.1

CVE-2024-41617 -

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arb…

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 29, 2024, 5:35 p.m.

9.1

CVSS3.1

CVE-2024-48144 -

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 28, 2024, 8:35 p.m.

8.4

CVSS3.1

CVE-2024-48546 -

Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

6.5

CVSS3.1

CVE-2024-48442 -

Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 8:35 p.m.

7.8

CVSS3.1

CVE-2024-45242 -

EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentia…

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 28, 2024, 7:35 p.m.
Total resulsts: 343947
Page 7636 of 34,395
Β« previous page Β» next page
Filters