5.5

CVSS3.1

CVE-2024-53151 - svcrdma: Address an integer overflow

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Address an integer overflow Dan Carpenter reports: > Commit 78147ca8b4a9 ("svcrdma: Add a "parsed chunk list" data > structure") from Jun 22, 2020 (linux-next), leads to the following > Smatch static checker warning: > >…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53157 - firmware: arm_scpi: Check the DVFS OPP count returned by the firmware

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Check the DVFS OPP count returned by the firmware Fix a kernel crash with the below call trace when the SCPI firmware returns OPP count of zero. dvfs_info.opp_count may be zero on some platforms during the re…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53146 - NFSD: Prevent a potential integer overflow

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so that decode_cb_compound…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

7.1

CVSS3.1

CVE-2024-53150 - ALSA: usb-audio: Fix out of bounds reads when finding clock sources

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descript…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

5.3

CVSS4.0

CVE-2018-25106 - webuidesigning NebulaX Theme Legacy.php nebula_send_to_hubspot sql injection

A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be initiated remotely. The pat…

πŸ“… Published: Dec. 23, 2024, 11 p.m. πŸ”„ Last Modified: July 13, 2025, 11:21 a.m.

8.1

CVSS3.1

CVE-2024-53961 - ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outsid…

πŸ“… Published: Dec. 23, 2024, 8:11 p.m. πŸ”„ Last Modified: April 16, 2025, 2:21 p.m.

7.8

CVSS3.1

CVE-2024-56363 - APTRS has SSTI vulnerability

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 temp…

πŸ“… Published: Dec. 23, 2024, 5:23 p.m. πŸ”„ Last Modified: Dec. 24, 2024, 1:32 a.m.

7.1

CVSS3.1

CVE-2024-56362 - Navidrome Stores JWT Secret in Plaintext in navidrome.db

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This…

πŸ“… Published: Dec. 23, 2024, 5:19 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 1:56 a.m.

6.3

CVSS4.0

CVE-2024-53276 - GHSL-2024-092: Open CORS policy in home-gallery

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow an attacker to view the images of home-gallery when it is using the default settings. The following express middleware allows any website to…

πŸ“… Published: Dec. 23, 2024, 5:13 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 10:15 p.m.

5.3

CVSS4.0

CVE-2024-53275 - GHSL-2024-091: DNS rebinding attack in home-gallery

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, the default setup of home-gallery is vulnerable to DNS rebinding. Home-gallery is set up without TLS and user authentication by default, leaving it vulnerable to DNS rebinding. In …

πŸ“… Published: Dec. 23, 2024, 5:13 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 10:15 p.m.
Total resulsts: 343921
Page 6864 of 34,393
Β« previous page Β» next page
Filters