7.3

CVSS3.1

CVE-2024-45801 - Tampering by prototype polution in DOMPurify

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the d…

πŸ“… Published: Sept. 16, 2024, 6:25 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 5:15 p.m.

4.6

CVSS4.0

CVE-2024-8661 - Concrete CMS version 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Prev…

Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 …

πŸ“… Published: Sept. 16, 2024, 5:37 p.m. πŸ”„ Last Modified: Dec. 16, 2024, 7:08 p.m.

6.8

CVSS4.0

CVE-2024-23984 -

Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS4.0

CVE-2024-24968 - microcode_ctl: Denial of Service

Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.8

CVSS4.0

CVE-2023-25546 -

Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2023-43753 -

Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2023-22351 -

Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2023-23904 -

NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2023-41833 -

A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-21781 -

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.

πŸ“… Published: Sept. 16, 2024, 4:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8555 of 34,919
Β« previous page Β» next page
Filters