5.5

CVSS3.1

CVE-2024-53157 - firmware: arm_scpi: Check the DVFS OPP count returned by the firmware

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Check the DVFS OPP count returned by the firmware Fix a kernel crash with the below call trace when the SCPI firmware returns OPP count of zero. dvfs_info.opp_count may be zero on some platforms during the reโ€ฆ

๐Ÿ“… Published: Dec. 24, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53146 - NFSD: Prevent a potential integer overflow

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so that decode_cb_compoundโ€ฆ

๐Ÿ“… Published: Dec. 24, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

7.1

CVSS3.1

CVE-2024-53150 - ALSA: usb-audio: Fix out of bounds reads when finding clock sources

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptโ€ฆ

๐Ÿ“… Published: Dec. 24, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

5.3

CVSS4.0

CVE-2018-25106 - webuidesigning NebulaX Theme Legacy.php nebula_send_to_hubspot sql injection

A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be initiated remotely. The patโ€ฆ

๐Ÿ“… Published: Dec. 23, 2024, 11 p.m. ๐Ÿ”„ Last Modified: July 13, 2025, 11:21 a.m.

8.1

CVSS3.1

CVE-2024-53961 - ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outsidโ€ฆ

๐Ÿ“… Published: Dec. 23, 2024, 8:11 p.m. ๐Ÿ”„ Last Modified: April 16, 2025, 2:21 p.m.

7.8

CVSS3.1

CVE-2024-56363 - APTRS has SSTI vulnerability

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 tempโ€ฆ

๐Ÿ“… Published: Dec. 23, 2024, 5:23 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2024, 1:32 a.m.

7.1

CVSS3.1

CVE-2024-56362 - Navidrome Stores JWT Secret in Plaintext in navidrome.db

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. Thisโ€ฆ

๐Ÿ“… Published: Dec. 23, 2024, 5:19 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 1:56 a.m.

6.3

CVSS4.0

CVE-2024-53276 - GHSL-2024-092: Open CORS policy in home-gallery

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow an attacker to view the images of home-gallery when it is using the default settings. The following express middleware allows any website toโ€ฆ

๐Ÿ“… Published: Dec. 23, 2024, 5:13 p.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 10:15 p.m.

5.3

CVSS4.0

CVE-2024-53275 - GHSL-2024-091: DNS rebinding attack in home-gallery

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, the default setup of home-gallery is vulnerable to DNS rebinding. Home-gallery is set up without TLS and user authentication by default, leaving it vulnerable to DNS rebinding. In โ€ฆ

๐Ÿ“… Published: Dec. 23, 2024, 5:13 p.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 10:15 p.m.

5.4

CVSS3.1

CVE-2024-56364 - Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue anโ€ฆ

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13.

๐Ÿ“… Published: Dec. 23, 2024, 3:52 p.m. ๐Ÿ”„ Last Modified: Dec. 28, 2024, 12:48 a.m.
Total resulsts: 343850
Page 6857 of 34,385
ยซ previous page ยป next page
Filters