9.8

CVSS3.1

CVE-2024-41618 -

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-45263 -

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Sept. 29, 2025, 3:02 p.m.

7.5

CVSS3.1

CVE-2024-48139 -

A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-40595 -

An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol informat…

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-48142 -

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-48540 -

Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2024-48542 -

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-45262 -

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2025, 5:54 p.m.

8.1

CVSS3.1

CVE-2024-48427 -

A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 12:07 a.m.

5.5

CVSS3.1

CVE-2024-48424 - assimp: heap-buffer-overflow in OpenDDLParser::parseStructure

A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.

πŸ“… Published: Oct. 24, 2024, midnight πŸ”„ Last Modified: June 10, 2025, 6:52 p.m.
Total resulsts: 349182
Page 8161 of 34,919
Β« previous page Β» next page
Filters