5.5

CVSS3.1

CVE-2024-47674 - mm: avoid leaving partial pfn mappings around in error case

In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings, there is no lifetime information associated with the mapping - it is just a raw mapp…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:54 a.m.

5.3

CVSS3.1

CVE-2024-48623 -

In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:13 p.m.

5.1

CVSS3.1

CVE-2024-44337 - gomarkdown/markdown: infinite loop via the paragraph function of parser/block.go

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of th…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.

4.9

CVSS3.1

CVE-2024-31955 -

An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 5:35 p.m.

5.5

CVSS3.1

CVE-2024-48278 -

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:27 p.m.

8.8

CVSS3.1

CVE-2024-35584 -

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: July 17, 2025, 5:33 p.m.

7.5

CVSS3.1

CVE-2024-44775 -

kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by sending a specially crafted MQTT CONNECT packet that triggers an unhandled null reference, leading to an immediate process termination.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 3, 2026, 5:16 p.m.

6.6

CVSS3.1

CVE-2024-48622 -

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2024-41344 -

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Aug. 1, 2025, 8:36 p.m.

6.5

CVSS3.1

CVE-2024-48712 -

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 8:27 p.m.
Total resulsts: 343992
Page 7777 of 34,400
Β« previous page Β» next page
Filters