7.4

CVSS3.1

CVE-2024-33423 -

Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language section.

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: April 14, 2025, 2:22 p.m.

7.4

CVSS3.1

CVE-2024-33306 -

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 4:46 p.m.

7.3

CVSS3.1

CVE-2024-33300 -

Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: June 10, 2025, 6:07 p.m.

5.5

CVSS3.1

CVE-2023-52650 - drm/tegra: dsi: Add missing check for of_find_device_by_node

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: dsi: Add missing check for of_find_device_by_node Add check for the return value of of_find_device_by_node() and return the error if it fails in order to avoid NULL pointer dereference.

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 7:40 a.m.

5.5

CVSS3.1

CVE-2024-27074 - media: go7007: fix a memleak in go7007_load_encoder

In the Linux kernel, the following vulnerability has been resolved: media: go7007: fix a memleak in go7007_load_encoder In go7007_load_encoder, bounce(i.e. go->boot_fw), is allocated without a deallocation thereafter. After the following call chain: saa7134_go7007_init |-> go7007_boot_encoder …

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:03 a.m.

8.1

CVSS3.1

CVE-2024-32212 -

SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: Sept. 19, 2025, 2:18 p.m.

7.8

CVSS3.1

CVE-2024-26944 - btrfs: zoned: fix use-after-free in do_zone_finish()

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix use-after-free in do_zone_finish() Shinichiro reported the following use-after-free triggered by the device replace operation in fstests btrfs/070. BTRFS info (device nullb1): scrub: finished on devid 1 with s…

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: Dec. 1, 2025, 3:16 p.m.

9.8

CVSS3.1

CVE-2023-46295 -

An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit this by sending a POST request to the vulnerable PHP page. An attacker can elevate to root permissions with Sudo.

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2024-27009 - s390/cio: fix race condition during online processing

In the Linux kernel, the following vulnerability has been resolved: s390/cio: fix race condition during online processing A race condition exists in ccw_device_set_online() that can cause the online process to fail, leaving the affected device in an inconsistent state. As a result, subsequent att…

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

5.5

CVSS3.1

CVE-2024-26993 - fs: sysfs: Fix reference leak in sysfs_break_active_protection()

In the Linux kernel, the following vulnerability has been resolved: fs: sysfs: Fix reference leak in sysfs_break_active_protection() The sysfs_break_active_protection() routine has an obvious reference leak in its error path. If the call to kernfs_find_and_get() fails then kn will be NULL, so th…

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.
Total resulsts: 349182
Page 10106 of 34,919
Β« previous page Β» next page
Filters