9.1

CVSS3.1

CVE-2024-53900 -

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:24 p.m.

2.2

CVSS3.1

CVE-2024-53564 -

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intention…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Sept. 23, 2025, 1 p.m.

7.5

CVSS3.1

CVE-2024-31669 -

rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: July 2, 2025, 8:36 p.m.

7.5

CVSS3.1

CVE-2024-53605 -

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-53939 -

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary command…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-53617 -

A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-53477 -

JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 1:44 p.m.

7

CVSS3.1

CVE-2024-39343 -

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mobility Management) module, which can lead to Denial of Servic…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: July 1, 2025, 3 p.m.

5.5

CVSS3.1

CVE-2024-53115 - drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle The 'vmw_user_object_buffer' function may return NULL with incorrect inputs. To avoid possible null pointer dereference, add a check whether the 'bo' is NU…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

5.5

CVSS3.1

CVE-2024-53109 - nommu: pass NULL argument to vma_iter_prealloc()

In the Linux kernel, the following vulnerability has been resolved: nommu: pass NULL argument to vma_iter_prealloc() When deleting a vma entry from a maple tree, it has to pass NULL to vma_iter_prealloc() in order to calculate internal state of the tree, but it passed a wrong argument. As a resu…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.
Total resulsts: 349182
Page 7662 of 34,919
Β« previous page Β» next page
Filters