CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2022-30360

    Last Modified: 31 Oct 2024

    OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required.

    Published: 25 Oct 2024
    5.3
    Medium

    CVE-2023-26248

    Last Modified: 15 Apr 2026

    The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an attacker to censor content by generating many Sybil peers whose peer IDs have a small distance from the content ID, thus hijacking the content resolution process.

    Published: 25 Oct 2024
    5.4
    Medium

    CVE-2024-37844

    Last Modified: 5 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 25 Oct 2024
    4.6
    Medium

    CVE-2024-37846

    Last Modified: 5 Nov 2024

    MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.

    Published: 25 Oct 2024
    7.2
    High

    CVE-2024-48226

    Last Modified: 31 Oct 2024

    Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.

    Published: 25 Oct 2024
    4.9
    Medium

    CVE-2024-48227

    Last Modified: 31 Oct 2024

    Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).

    Published: 25 Oct 2024
    9.8
    Critical

    CVE-2024-48204

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.

    Published: 25 Oct 2024
    7.2
    High

    CVE-2024-48218

    Last Modified: 31 Oct 2024

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.

    Published: 25 Oct 2024
    7.2
    High

    CVE-2024-48222

    Last Modified: 31 Oct 2024

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.

    Published: 25 Oct 2024
    7.2
    High

    CVE-2024-48223

    Last Modified: 31 Oct 2024

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

    Published: 25 Oct 2024
    6.5
    Medium

    CVE-2024-48225

    Last Modified: 31 Oct 2024

    Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.

    Published: 25 Oct 2024
    7.2
    High

    CVE-2024-48229

    Last Modified: 31 Oct 2024

    funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.

    Published: 25 Oct 2024
    7.2
    High

    CVE-2024-48230

    Last Modified: 31 Oct 2024

    funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.

    Published: 25 Oct 2024
    4.9
    Medium

    CVE-2024-48232

    Last Modified: 7 Jul 2025

    An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.

    Published: 25 Oct 2024
    4.8
    Medium

    CVE-2024-48233

    Last Modified: 7 Jul 2025

    mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter.

    Published: 25 Oct 2024
    6.5
    Medium

    CVE-2024-48235

    Last Modified: 18 Apr 2025

    An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

    Published: 25 Oct 2024
    6.5
    Medium

    CVE-2024-48236

    Last Modified: 18 Apr 2025

    An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file

    Published: 25 Oct 2024
    9.8
    Critical

    CVE-2024-48237

    Last Modified: 17 Apr 2025

    WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

    Published: 25 Oct 2024
    4.7
    Medium

    CVE-2024-48238

    Last Modified: 17 Apr 2025

    WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.

    Published: 25 Oct 2024
    4.8
    Medium

    CVE-2024-48239

    Last Modified: 17 Apr 2025

    An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).

    Published: 25 Oct 2024
    6.3
    Medium

    CVE-2024-48343

    Last Modified: 28 May 2025

    A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page.

    Published: 25 Oct 2024
    6.1
    Medium

    CVE-2024-48396

    Last Modified: 15 Apr 2026

    AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.

    Published: 25 Oct 2024
    9.8
    Critical

    CVE-2024-48428

    Last Modified: 19 Mar 2025

    An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.

    Published: 25 Oct 2024
    6.5
    Medium

    CVE-2024-48450

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

    Published: 25 Oct 2024
    7.3
    High

    CVE-2024-48459

    Last Modified: 15 Apr 2026

    A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.24A1V16.03.29.50;V16.03.29.50;V16.03.29.50. An attacker can exploit this vulnerability by constructing a malicious payload to execute commands and further obtain shell access to the router's file system with the highest privileges.

    Published: 25 Oct 2024
    9.8
    Critical

    CVE-2024-48579

    Last Modified: 28 Apr 2025

    SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.

    Published: 25 Oct 2024
    5.1
    Medium

    CVE-2024-10350

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024
    5.5
    Medium

    CVE-2024-49750

    Last Modified: 6 Nov 2024

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the `passcode` parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. Snowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes the issue. In addition to upgrading, users should review their logs for any potentially sensitive information that may have been captured.

    Published: 24 Oct 2024
    2
    Low

    CVE-2024-10372

    Last Modified: 6 Nov 2024

    A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to insecure temporary file. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Oct 2024
    4.6
    Medium

    CVE-2024-49762

    Last Modified: 15 Apr 2026

    Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are encrypted when using TLS, many webservers (including ones officially documented for use with Pterodactyl) will log query parameters in plain-text, storing a user's password in plain text. Prior to version 1.11.8, if a malicious user obtains access to these logs they could potentially authenticate against a user's account; assuming they are able to discover the account's email address or username separately. This problem has been patched in version 1.11.8. There are no workarounds at this time. There is not a direct vulnerability within the software as it relates to logs generated by intermediate components such as web servers or Layer 7 proxies. Updating to `v1.11.8` or adding the linked patch manually are the only ways to avoid this problem. As this vulnerability relates to historical logging of sensitive data, users who have ever disabled 2FA on a Panel (self-hosted or operated by a company) should change their passwords and consider enabling 2FA if it was left disabled. While it's unlikely that their account swill be compromised by this vulnerability, it's not impossible. Panel administrators should consider clearing any access logs that may contain sensitive data.

    Published: 24 Oct 2024
    7.1
    High

    CVE-2024-49760

    Last Modified: 6 Nov 2024

    OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versions prior to 3.8.3, it does not check that the resulting path is in the expected directory, which means that this command could be exploited to read other JSON files on the file system. Version 3.8.3 addresses this issue.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-49359

    Last Modified: 22 Sept 2025

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users to list the contents of any directory on the server. By manipulating the path parameter, attackers can access sensitive system directories such as `/etc`, potentially exposing critical configuration files and increasing the risk of further attacks. As of time of publication, no known patched versions are available.

    Published: 24 Oct 2024
    5.3
    Medium

    CVE-2024-10371

    Last Modified: 30 Oct 2024

    A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024
    6.9
    Medium

    CVE-2024-10370

    Last Modified: 30 Oct 2024

    A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcustind.php. The manipulation of the argument refno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024
    5.3
    Medium

    CVE-2024-49358

    Last Modified: 22 Sept 2025

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is incorrect. This behavior can be exploited for username enumeration, allowing attackers to determine whether a user exists in the system or not. Attackers can leverage this information in further attacks, such as credential stuffing or targeted password brute-forcing. As of time of publication, no known patched versions are available.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-49357

    Last Modified: 22 Sept 2025

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json`, expose sensitive data like installed applications and system information without requiring any authentication or authorization. This sensitive data leak can be exploited by attackers to gain detailed knowledge about the system setup, installed applications, and other critical information. As of time of publication, no known patched versions are available.

    Published: 24 Oct 2024
    5.3
    Medium

    CVE-2024-48932

    Last Modified: 5 Nov 2025

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization. This vulnerability could be exploited by an attacker to enumerate usernames and leverage them for further attacks, such as brute-force or phishing campaigns. As of time of publication, no known patched versions are available.

    Published: 24 Oct 2024
    6.9
    Medium

    CVE-2024-10369

    Last Modified: 30 Oct 2024

    A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /addcustcom.php. The manipulation of the argument refno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024
    6.9
    Medium

    CVE-2024-10368

    Last Modified: 30 Oct 2024

    A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024
    7.5
    High

    CVE-2024-48931

    Last Modified: 6 Nov 2024

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=<token>&files=<file_path>` is vulnerable to arbitrary file reading due to improper input validation. By manipulating the `files` parameter, authenticated users can read sensitive system files, including `/etc/shadow`, which contains password hashes for all users. This vulnerability exposes critical system data and poses a high risk for privilege escalation or system compromise. The vulnerability occurs because the API endpoint does not validate or restrict file paths provided via the `files` parameter. An attacker can exploit this by manipulating the file path to access sensitive files outside the intended directory. As of time of publication, no known patched versions are available.

    Published: 24 Oct 2024
    9.1
    Critical

    CVE-2024-47883

    Last Modified: 29 Oct 2024

    The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or templates. This works: "opening a connection" to these URLs opens the local file. However, prior to version 1.2.6, if a `file:/` URL is directly given where a relative path (resource name) is expected, this is also accepted in some code paths; the app then fetches the file, from a remote machine if indicated, and uses it as if it was a trusted part of the app's codebase. This leads to multiple weaknesses and potential weaknesses. An attacker that has network access to the application could use it to gain access to files, either on the the server's filesystem (path traversal) or shared by nearby machines (server-side request forgery with e.g. SMB). An attacker that can lead or redirect a user to a crafted URL belonging to the app could cause arbitrary attacker-controlled JavaScript to be loaded in the victim's browser (cross-site scripting). If an app is written in such a way that an attacker can influence the resource name used for a template, that attacker could cause the app to fetch and execute an attacker-controlled template (remote code execution). Version 1.2.6 contains a patch.

    Published: 24 Oct 2024
    5.9
    Medium

    CVE-2024-47882

    Last Modified: 28 Oct 2024

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the exception message and exception traceback without escaping HTML tags, enabling injection into the page if an attacker can reliably produce an error with an attacker-influenced message. It appears that the only way to reach this code in OpenRefine itself is for an attacker to somehow convince a victim to import a malicious file, which may be difficult. However, out-of-tree extensions may add their own calls to `respondWithErrorPage`. Version 3.8.3 has a fix for this issue.

    Published: 24 Oct 2024
    8.1
    High

    CVE-2024-47881

    Last Modified: 28 Oct 2024

    OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.

    Published: 24 Oct 2024
    8.1
    High

    CVE-2024-47880

    Last Modified: 30 Oct 2024

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An attacker could lead a user to a malicious page that submits a form POST that contains embedded JavaScript code. This code would then be included in the response, along with an attacker-controlled `Content-Type` header, and so potentially executed in the victim's browser as if it was part of OpenRefine. The attacker-provided code can do anything the user can do, including deleting projects, retrieving database passwords, or executing arbitrary Jython or Closure expressions, if those extensions are also present. The attacker must know a valid project ID of a project that contains at least one row. Version 3.8.3 fixes the issue.

    Published: 24 Oct 2024
    8.1
    High

    CVE-2024-10327

    Last Modified: 15 Apr 2026

    A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the notification banner and selects an option, both options allow the authentication to succeed. The ContextExtension feature is one of several push mechanisms available when using Okta Verify Push on iOS devices. The vulnerable flows include: * When a user is presented with a notification on a locked screen, the user presses on the notification directly and selects their reply without unlocking the device; * When a user is presented with a notification on the home screen and drags the notification down and selects their reply; * When an Apple Watch is used to reply directly to a notification. A pre-condition for this vulnerability is that the user must have enrolled in Okta Verify while the Okta customer was using Okta Classic. This applies irrespective of whether the organization has since upgraded to Okta Identity Engine.

    Published: 24 Oct 2024
    7.6
    High

    CVE-2024-47879

    Last Modified: 4 Dec 2024

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled expression to be executed. The expression can contain arbitrary Clojure or Python code. The attacker must know a valid project ID of a project that contains at least one row, and the attacker must convince the victim to open a malicious webpage. Version 3.8.3 fixes the issue.

    Published: 24 Oct 2024
    9.8
    Critical

    CVE-2024-7763

    Last Modified: 30 Oct 2024

    In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

    Published: 24 Oct 2024
    8.1
    High

    CVE-2024-47878

    Last Modified: 30 Oct 2024

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `<script>` tag in the output, so without escaping. An attacker could lead or redirect a user to a crafted URL containing JavaScript code, which would then cause that code to be executed in the victim's browser as if it was part of OpenRefine. Version 3.8.3 fixes this issue.

    Published: 24 Oct 2024
    5.1
    Medium

    CVE-2024-10355

    Last Modified: 30 Oct 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoice.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024
    5.1
    Medium

    CVE-2024-10354

    Last Modified: 30 Oct 2024

    A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/print.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Oct 2024