4.4

CVSS3.1

CVE-2024-20091 -

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1701.

๐Ÿ“… Published: Oct. 7, 2024, 2:35 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2024, 3:35 a.m.

6.7

CVSS3.1

CVE-2024-20090 -

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1703.

๐Ÿ“… Published: Oct. 7, 2024, 2:35 a.m. ๐Ÿ”„ Last Modified: April 25, 2025, 6:37 p.m.

8.7

CVSS4.0

CVE-2024-9565 - D-Link DIR-605L formSetPassword buffer overflow

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The โ€ฆ

๐Ÿ“… Published: Oct. 7, 2024, 12:31 a.m. ๐Ÿ”„ Last Modified: Oct. 8, 2024, 6:39 p.m.

8.7

CVSS4.0

CVE-2024-9564 - D-Link DIR-605L formWlanWizardSetup buffer overflow

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the attack remotely. The exโ€ฆ

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 8, 2024, 6:38 p.m.

9.8

CVSS3.1

CVE-2024-45874 -

A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe.

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-42831 -

A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-44068 -

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 3:52 p.m.

6.1

CVSS3.1

CVE-2024-28710 -

Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:15 p.m.

8.4

CVSS3.1

CVE-2024-46278 -

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: June 4, 2025, 5:08 p.m.

7.1

CVSS3.1

CVE-2024-45932 -

Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.

๐Ÿ“… Published: Oct. 7, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 11, 2024, 1:21 p.m.
Total resulsts: 349182
Page 8380 of 34,919
ยซ previous page ยป next page
Filters