5.5

CVSS3.1

CVE-2024-53097 - mm: krealloc: Fix MTE false alarm in __do_krealloc

In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc This patch addresses an issue introduced by commit 1a83a716ec233 ("mm: krealloc: consider spare memory for __GFP_ZERO") which causes MTE (Memory Tagging Extension) to falsely rep…

πŸ“… Published: Nov. 25, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

6.1

CVSS3.1

CVE-2024-53599 -

A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: Nov. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-50671 -

Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs gra…

πŸ“… Published: Nov. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2024-53102 - kernel: nvme: make keep-alive synchronous operation

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Nov. 25, 2024, midnight πŸ”„ Last Modified: Dec. 12, 2024, 4:15 p.m.

8

CVSS3.1

CVE-2024-53554 -

A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details.

πŸ“… Published: Nov. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-53930 -

WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.

πŸ“… Published: Nov. 25, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-11646 - 1000 Projects Beauty Parlour Management System edit-services.php sql injection

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-services.php. The manipulation of the argument sername leads to sql injection. The attack can be launched remote…

πŸ“… Published: Nov. 24, 2024, 11:31 p.m. πŸ”„ Last Modified: Nov. 26, 2024, 3:54 p.m.

9

CVSS3.1

CVE-2024-11666 - Unauthenticated Remote Command Injection in eCharge Salia PLCC

Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated usersΒ  suitably positioned on the network between an …

πŸ“… Published: Nov. 24, 2024, 10:36 p.m. πŸ”„ Last Modified: Dec. 3, 2024, 3:40 p.m.

8.8

CVSS3.1

CVE-2024-11665 - Unauthenticated Remote Command Injection

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.

πŸ“… Published: Nov. 24, 2024, 10:32 p.m. πŸ”„ Last Modified: Dec. 4, 2024, 5:43 p.m.

4.8

CVSS3.1

CVE-2024-11233 - Single byte overread with convert.quoted-printable-decode filter

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error inΒ convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

πŸ“… Published: Nov. 24, 2024, 1:08 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.
Total resulsts: 345202
Page 7316 of 34,521
Β« previous page Β» next page
Filters