7.3

CVSS3.1

CVE-2024-40511 -

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: April 23, 2025, 3:57 p.m.

5.5

CVSS3.1

CVE-2024-46832 - MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed

In the Linux kernel, the following vulnerability has been resolved: MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed This avoids warning: [ 0.118053] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:283 Caused by get_c0_compare_int on second…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:53 a.m.

4.8

CVSS3.1

CVE-2024-46333 -

An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 7:12 p.m.

7.8

CVSS3.1

CVE-2024-46820 - drm/amdgpu/vcn: remove irq disabling in vcn 5 suspend

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: remove irq disabling in vcn 5 suspend We do not directly enable/disable VCN IRQ in vcn 5.0.0. And we do not handle the IRQ state as well. So the calls to disable IRQ and set state are removed. This effectively get…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:35 a.m.

6.1

CVSS3.1

CVE-2024-46470 -

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 7:19 p.m.

5.5

CVSS3.1

CVE-2024-46827 - wifi: ath12k: fix firmware crash due to invalid peer nss

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix firmware crash due to invalid peer nss Currently, if the access point receives an association request containing an Extended HE Capabilities Information Element with an invalid MCS-NSS, it triggers a firmware cr…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:35 a.m.

6.1

CVSS3.1

CVE-2024-46453 -

A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 4:15 p.m.

7.1

CVSS3.1

CVE-2024-46865 - fou: fix initialization of grc

In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-46863 - ASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, and we test !link->num_adr as a condition to end the loop in hda_sdw_machine_select(). So an empty item in struct…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:36 a.m.

5.5

CVSS3.1

CVE-2024-46862 - ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, and we test !link->num_adr as a condition to end the loop in hda_sdw_machine_select(). So an empty item in struct…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:36 a.m.
Total resulsts: 349182
Page 8454 of 34,919
Β« previous page Β» next page
Filters