9.6

CVSS3.1

CVE-2024-38889 -

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Feb. 20, 2026, 8:39 p.m.

7.5

CVSS3.1

CVE-2024-41310 -

AndServer 2.1.12 is vulnerable to Directory Traversal.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: March 18, 2025, 8:15 p.m.

5.3

CVSS3.1

CVE-2024-33892 -

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

6.6

CVSS3.1

CVE-2024-33895 -

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

7.8

CVSS3.1

CVE-2024-38884 -

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 2:11 p.m.

5.3

CVSS3.1

CVE-2024-42460 - elliptic: nodejs/elliptic: ECDSA signature malleability due to missing checks

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.

9.8

CVSS3.1

CVE-2024-38887 -

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 20, 2024, 4:17 p.m.

5.3

CVSS3.1

CVE-2024-41517 -

An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding privileges.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2024, 9:35 p.m.

5.3

CVSS3.1

CVE-2024-42459 - elliptic: nodejs/elliptic: EDDSA signature malleability due to missing signature length check

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.

7.5

CVSS3.1

CVE-2024-38885 -

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.

๐Ÿ“… Published: Aug. 2, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 2:11 p.m.
Total resulsts: 349182
Page 8968 of 34,919
ยซ previous page ยป next page
Filters