5.5

CVSS3.1

CVE-2024-57950 - drm/amd/display: Initialize denominator defaults to 1

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to 1 [WHAT & HOW] Variables, used as denominators and maybe not assigned to other values, should be initialized to non-zero to avoid DIVIDE_BY_ZERO, as reported by Coverity. (cher…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21686 - kernel: io_uring/rsrc: require cloned buffers to share accounting contexts

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: May 20, 2025, 2:15 p.m.

7.3

CVSS3.1

CVE-2024-57177 -

A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-46432 -

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 6:13 p.m.

5.9

CVSS3.1

CVE-2024-57178 -

An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or manipulate the softwar…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-57408 -

An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 8:25 p.m.

6.5

CVSS3.1

CVE-2024-46437 -

A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials, by sending a special…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:38 p.m.

5.5

CVSS3.1

CVE-2025-21691 - cachestat: fix page cache statistics permission checking

In the Linux kernel, the following vulnerability has been resolved: cachestat: fix page cache statistics permission checking When the 'cachestat()' system call was added in commit cf264e1329fb ("cachestat: implement cachestat syscall"), it was meant to be a much more convenient (and performant) v…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-21690 - scsi: storvsc: Ratelimit warning logs to prevent VM denial of service

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent error in the hypervisor, the SCSI warning for failed I/O can flood the kernel log and max out CPU utilization, preventing troubleshooti…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:28 p.m.

7.3

CVSS3.1

CVE-2024-57407 -

An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6811 of 34,919
Β« previous page Β» next page
Filters