5.1

CVSS4.0

CVE-2024-10477 - LinZhaoguan pb-cms Permission Management Page admin#permissions cross site scripting

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploi…

πŸ“… Published: Oct. 29, 2024, 12:31 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 3 p.m.

7.5

CVSS3.1

CVE-2024-44080 -

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 7:33 p.m.

5.5

CVSS3.1

CVE-2024-50078 - Bluetooth: Call iso_exit() on module unload

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Call iso_exit() on module unload If iso_init() has been called, iso_exit() must be called on module unload. Without that, the struct proto that iso_init() registered with proto_register() becomes invalid, which could c…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

7.8

CVSS3.1

CVE-2024-9632 - Xorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerability

A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org serve…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: March 18, 2026, 4:01 p.m.

5.5

CVSS3.1

CVE-2024-50072 - x86/bugs: Use code segment selector for VERW operand

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Use code segment selector for VERW operand Robert Gill reported below #GP in 32-bit mode when dosemu software was executing vm86() system call: general protection fault: 0000 [#1] PREEMPT SMP CPU: 4 PID: 4610 Comm:…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

10

CVSS3.1

CVE-2024-51567 -

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in t…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 7:02 p.m.

5.5

CVSS3.1

CVE-2024-50079 - io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work

In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work When the sqpoll is exiting and cancels pending work items, it may need to run task_work. If this happens from within io_uring_cancel_generic(), then it may…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

7.8

CVSS3.1

CVE-2024-50084 - net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()

In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() Commit a3c1e45156ad ("net: microchip: vcap: Fix use-after-free error in kunit test") fixed the use-after-free error, but introduced below memory leaks by r…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 12:59 p.m.

7.8

CVSS3.1

CVE-2024-50073 - tty: n_gsm: Fix use-after-free in gsm_cleanup_mux

In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Fix use-after-free in gsm_cleanup_mux BUG: KASAN: slab-use-after-free in gsm_cleanup_mux+0x77b/0x7b0 drivers/tty/n_gsm.c:3160 [n_gsm] Read of size 8 at addr ffff88815fe99c00 by task poc/3379 CPU: 0 UID: 0 PID: 3379 Co…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

5.5

CVSS3.1

CVE-2024-50080 - ublk: don't allow user copy for unprivileged device

In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unpri…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.
Total resulsts: 343924
Page 7581 of 34,393
Β« previous page Β» next page
Filters