4.4

CVSS4.0

CVE-2024-33658 - Buffer Overflow Vulnerability In OFBD

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of this vulnerability may lead to privilege escalation and potentially arbitrary code execution, and impact Integrity.

πŸ“… Published: Nov. 12, 2024, 3:01 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 2:28 p.m.

5.2

CVSS4.0

CVE-2024-33660 - Potential Firmware update without integrity check

An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.

πŸ“… Published: Nov. 12, 2024, 3 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 2:32 p.m.

7.2

CVSS3.1

CVE-2024-42442 - Runtime Service Access outside SMRAM

APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations within the bounds of a memory buffer over the network. A successful exploitation of this vulnerability may lead to code execution outside of the intended System Management Mode.

πŸ“… Published: Nov. 12, 2024, 3 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 2:29 p.m.

5.1

CVSS4.0

CVE-2024-11130 - ZZCMS msg.php cross site scripting

A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/msg.php. The manipulation of the argument keyword leads to cross site scripting. The attack may be launched remotely. The exploit has been disclos…

πŸ“… Published: Nov. 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 5:57 p.m.

5.3

CVSS4.0

CVE-2024-11127 - code-projects Job Recruitment admin.php sql injection

A vulnerability was found in code-projects Job Recruitment up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin.php. The manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit …

πŸ“… Published: Nov. 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 5:29 p.m.

6.5

CVSS3.1

CVE-2024-51566 - bhyve(8) NVMe driver to guest-induced infinite loops.

The NVMe driver queue processing is vulernable to guest-induced infinite loops.

πŸ“… Published: Nov. 12, 2024, 2:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-51565 - bhyve(8) hda driver buffer over-read

The hda driver is vulnerable to a buffer over-read from a guest-controlled value.

πŸ“… Published: Nov. 12, 2024, 2:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-37365 - FactoryTalk View ME Remote Code Execution Vulnerability via Project Save Path

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate…

πŸ“… Published: Nov. 12, 2024, 2:52 p.m. πŸ”„ Last Modified: Nov. 12, 2024, 7:04 p.m.

7.5

CVSS3.1

CVE-2024-51564 - bhyve(8) infinite loop in the hda audio driver

A guest can trigger an infinite loop in the hda audio driver.

πŸ“… Published: Nov. 12, 2024, 2:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-51563 - bhyve(8) virtio_vq_recordon time-of-check to time-of-use race

The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.

πŸ“… Published: Nov. 12, 2024, 2:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7933 of 34,919
Β« previous page Β» next page
Filters