Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-38424 Use After Free vulnerability in Qualcomm products
Memory corruption during GNSS HAL process initialization.
local
low complexity
qualcomm CWE-416
7.8
2024-11-04 CVE-2024-10760 SQL Injection vulnerability in Anisha University Event Management System 1.0
A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical.
network
low complexity
anisha CWE-89
7.5
2024-11-04 CVE-2024-10759 SQL Injection vulnerability in Angeljudesuarez Farm Management System 1.0
A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical.
network
low complexity
angeljudesuarez CWE-89
8.8
2024-11-04 CVE-2024-10749 Deserialization of Untrusted Data vulnerability in Thinkadmin
A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67.
network
high complexity
thinkadmin CWE-502
8.1
2024-11-03 CVE-2024-10742 SQL Injection vulnerability in Anisha Wazifa System 1.0
A vulnerability was found in code-projects Wazifa System 1.0 and classified as critical.
network
low complexity
anisha CWE-89
7.5
2024-11-02 CVE-2024-51774 Improper Certificate Validation vulnerability in Qbittorrent
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
network
high complexity
qbittorrent CWE-295
8.1
2024-11-01 CVE-2024-9191 Incorrect Default Permissions vulnerability in Okta Verify
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins.
local
low complexity
okta CWE-276
7.8
2024-11-01 CVE-2024-48353 Insecure Storage of Sensitive Information vulnerability in Yealink Meeting Server
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
network
low complexity
yealink CWE-922
7.5
2024-11-01 CVE-2024-48352 Unspecified vulnerability in Yealink Meeting Server
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
network
low complexity
yealink
7.5
2024-11-01 CVE-2024-51244 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
network
low complexity
draytek CWE-78
8.8