6.2

CVSS3.1

CVE-2024-48540 -

Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 4:35 p.m.

8.4

CVSS3.1

CVE-2024-48545 -

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

5.3

CVSS3.1

CVE-2024-40595 -

An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol informat…

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

8.4

CVSS3.1

CVE-2024-48544 -

Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.

7.5

CVSS3.1

CVE-2024-48141 -

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 7:35 p.m.

8.8

CVSS3.1

CVE-2024-45262 -

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2025, 5:54 p.m.

8.1

CVSS3.1

CVE-2024-48427 -

A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 12:07 a.m.

5.5

CVSS3.1

CVE-2024-48424 - assimp: heap-buffer-overflow in OpenDDLParser::parseStructure

A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: June 10, 2025, 6:52 p.m.

9.8

CVSS3.1

CVE-2024-41618 -

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 29, 2024, 5:35 p.m.

8.4

CVSS3.1

CVE-2024-48542 -

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 12:56 p.m.
Total resulsts: 344111
Page 7654 of 34,412
Β« previous page Β» next page
Filters