5.5

CVSS3.1

CVE-2024-26947 - ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses

In the Linux kernel, the following vulnerability has been resolved: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses Since commit a4d5613c4dc6 ("arm: extend pfn_valid to take into account freed memory map alignment") changes the semantics of pfn_valid() to check presenc…

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: Sept. 18, 2025, 2:13 p.m.

5.5

CVSS3.1

CVE-2024-27072 - media: usbtv: Remove useless locks in usbtv_video_free()

In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Remove useless locks in usbtv_video_free() Remove locks calls in usbtv_video_free() because are useless and may led to a deadlock as reported here: https://syzkaller.appspot.com/x/bisect.txt?x=166dc872180000 Also re…

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

5.5

CVSS3.1

CVE-2024-27078 - media: v4l2-tpg: fix some memleaks in tpg_alloc

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-tpg: fix some memleaks in tpg_alloc In tpg_alloc, resources should be deallocated in each and every error-handling paths, since they are allocated in for statements. Otherwise there would be memleaks because tpg_free …

πŸ“… Published: May 1, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:03 a.m.

7.8

CVSS3.1

CVE-2024-4192 - Stack-based Buffer Overflow vulnerability in Delta Electronics CNCSoft-G2 DOPSoft

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

πŸ“… Published: April 30, 2024, 11:01 p.m. πŸ”„ Last Modified: July 10, 2025, 3:54 p.m.

7.3

CVSS3.1

CVE-2024-4349 - SourceCodester Pisay Online E-Learning System controller.php unrestricted upload

A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to unrestricted upload. The attack can be launch…

πŸ“… Published: April 30, 2024, 11 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 1:10 p.m.

7.1

CVSS3.1

CVE-2024-32970 - Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex

Phlex is a framework for building object-oriented views in Ruby. In affected versions there is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Since the last two vulnerabilities https://github.com/phlex-ruby/phlex/security/advisories/GHS…

πŸ“… Published: April 30, 2024, 10:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-4348 - osCommerce all-products cross site scripting

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…

πŸ“… Published: April 30, 2024, 10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2024-3746 - Measuresoft ScadaPro Improper Access Control

The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files.

πŸ“… Published: April 30, 2024, 7:45 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 9:23 p.m.

9.1

CVSS3.1

CVE-2024-3411 - Insufficient Randomness When Validating an IPMI Authenticated Session

Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID or weak BMC Random Number to bypass security controls using spoofed IPMI packets to manage BMC device.

πŸ“… Published: April 30, 2024, 6:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-23463 - Anti-Tampering bypass via Repair App functionality

Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1

πŸ“… Published: April 30, 2024, 4:17 p.m. πŸ”„ Last Modified: March 2, 2026, 7:37 p.m.
Total resulsts: 349182
Page 10121 of 34,919
Β« previous page Β» next page
Filters