5.5

CVSS3.1

CVE-2024-47674 - mm: avoid leaving partial pfn mappings around in error case

In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings, there is no lifetime information associated with the mapping - it is just a raw mapp…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:54 a.m.

5.3

CVSS3.1

CVE-2024-48623 -

In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:13 p.m.

4.9

CVSS3.1

CVE-2024-31955 -

An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-48278 -

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:27 p.m.

8.8

CVSS3.1

CVE-2024-35584 -

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: July 17, 2025, 5:33 p.m.

7.5

CVSS3.1

CVE-2024-44775 -

kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by sending a specially crafted MQTT CONNECT packet that triggers an unhandled null reference, leading to an immediate process termination.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 3, 2026, 5:16 p.m.

6.6

CVSS3.1

CVE-2024-48622 -

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2024-41344 -

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Aug. 1, 2025, 8:36 p.m.

6.5

CVSS3.1

CVE-2024-48712 -

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 8:27 p.m.

7.6

CVSS3.1

CVE-2024-48282 -

A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:12 p.m.
Total resulsts: 349182
Page 8296 of 34,919
Β« previous page Β» next page
Filters