|
305541
|
4.7 |
MEDIUM
Network
|
ovaledge
|
ovaledge
|
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADM…
|
CWE-863
Incorrect Authorization
|
CVE-2022-30356
|
2024-11-1 01:31 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305542
|
4.3 |
MEDIUM
Network
|
gaizhenbiao
|
chuanhuchatgpt
|
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a…
|
NVD-CWE-noinfo
|
CVE-2024-8143
|
2024-11-1 01:23 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305543
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
|
CWE-89
SQL Injection
|
CVE-2024-48230
|
2024-11-1 00:57 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305544
|
7.5 |
HIGH
Network
|
mintplexlabs
|
anythingllm
|
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in s…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-7783
|
2024-11-1 00:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305545
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
|
CWE-89
SQL Injection
|
CVE-2024-48229
|
2024-11-1 00:49 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305546
|
4.9 |
MEDIUM
Network
|
funadmin
|
funadmin
|
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
|
NVD-CWE-noinfo
|
CVE-2024-48227
|
2024-11-1 00:48 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305547
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
|
CWE-89
SQL Injection
|
CVE-2024-48223
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305548
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
|
CWE-89
SQL Injection
|
CVE-2024-48222
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305549
|
7.2 |
HIGH
Network
|
funadmin
|
funadmin
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
|
CWE-89
SQL Injection
|
CVE-2024-48218
|
2024-11-1 00:44 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305550
|
9.1 |
CRITICAL
Network
|
langchain
|
langchain
|
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite ex…
|
CWE-22
Path Traversal
|
CVE-2024-7774
|
2024-11-1 00:39 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|