9.8

CVSS3.1

CVE-2024-48781 -

An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Oct. 16, 2024, 7:35 p.m.

6.5

CVSS3.1

CVE-2024-48710 -

In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 8:27 p.m.

8.1

CVSS3.1

CVE-2024-41311 -

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 24, 2025, 2:41 p.m.

5.3

CVSS3.1

CVE-2024-48624 -

In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:02 p.m.

7.6

CVSS3.1

CVE-2024-48279 -

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:19 p.m.

7.6

CVSS3.1

CVE-2024-48280 -

A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:18 p.m.

9.8

CVSS3.1

CVE-2024-48779 -

An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Oct. 17, 2024, 5:35 p.m.

5.5

CVSS3.1

CVE-2024-47674 - mm: avoid leaving partial pfn mappings around in error case

In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings, there is no lifetime information associated with the mapping - it is just a raw mapp…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:54 a.m.

5.3

CVSS3.1

CVE-2024-48623 -

In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:13 p.m.

5.1

CVSS3.1

CVE-2024-44337 - gomarkdown/markdown: infinite loop via the paragraph function of parser/block.go

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of th…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.
Total resulsts: 343979
Page 7775 of 34,398
Β« previous page Β» next page
Filters