|
305681
|
7.5 |
HIGH
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in Zi…
|
CWE-22
Path Traversal
|
CVE-2024-49359
|
2024-11-7 00:27 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305682
|
5.3 |
MEDIUM
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-49358
|
2024-11-7 00:27 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305683
|
5.5 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-47402
|
2024-11-7 00:26 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305684
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47137
|
2024-11-7 00:26 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305685
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.
|
CWE-415
Double Free
|
CVE-2024-47404
|
2024-11-7 00:25 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305686
|
5.3 |
MEDIUM
Network
|
zimaspace
|
zimaos
|
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unau…
|
CWE-862
Missing Authorization
|
CVE-2024-48932
|
2024-11-7 00:25 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305687
|
7.8 |
HIGH
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47797
|
2024-11-7 00:24 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305688
|
7.5 |
HIGH
Network
|
anisha
|
e-health_care_system
|
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the ar…
|
CWE-89
SQL Injection
|
CVE-2024-10810
|
2024-11-7 00:16 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305689
|
7.5 |
HIGH
Network
|
anisha
|
e-health_care_system
|
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argume…
|
CWE-89
SQL Injection
|
CVE-2024-10809
|
2024-11-7 00:14 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305690
|
7.5 |
HIGH
Network
|
anisha
|
e-health_care_system
|
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the …
|
CWE-89
SQL Injection
|
CVE-2024-10808
|
2024-11-7 00:14 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|