8.4

CVSS3.1

CVE-2024-48544 -

Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

7.5

CVSS3.1

CVE-2024-48141 -

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 25, 2024, 7:35 p.m.

8.8

CVSS3.1

CVE-2024-45262 -

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 15, 2025, 5:54 p.m.

8.1

CVSS3.1

CVE-2024-48427 -

A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2024, 12:07 a.m.

5.5

CVSS3.1

CVE-2024-48424 - assimp: heap-buffer-overflow in OpenDDLParser::parseStructure

A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: June 10, 2025, 6:52 p.m.

9.8

CVSS3.1

CVE-2024-41618 -

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 29, 2024, 5:35 p.m.

8.4

CVSS3.1

CVE-2024-48542 -

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

7.2

CVSS3.1

CVE-2024-48454 -

An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 12:49 a.m.

8.8

CVSS3.1

CVE-2024-48441 -

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

๐Ÿ“… Published: Oct. 24, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 25, 2024, 8:35 p.m.

3.6

CVSS3.1

CVE-2023-50355 - HCL Sametime is impacted by generation of error messages containing sensitive information

HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

๐Ÿ“… Published: Oct. 23, 2024, 10:17 p.m. ๐Ÿ”„ Last Modified: Oct. 31, 2024, 3:18 p.m.
Total resulsts: 343968
Page 7640 of 34,397
ยซ previous page ยป next page
Filters