5.5

CVSS3.1

CVE-2023-52915 - media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious …

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:17 a.m.

9.8

CVSS3.1

CVE-2024-45771 -

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 2:03 p.m.

5.4

CVSS3.1

CVE-2024-44837 -

A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user parameter.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Sept. 12, 2024, 4:17 p.m.

9.1

CVSS3.1

CVE-2024-45758 -

H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON document containing a connection_url property with an…

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Sept. 29, 2025, 1:56 p.m.

9.8

CVSS3.1

CVE-2024-44402 -

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Sept. 10, 2024, 4:58 p.m.

8

CVSS3.1

CVE-2024-44844 -

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Sept. 11, 2024, 4:24 p.m.

9.8

CVSS3.1

CVE-2024-44838 -

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 2:04 p.m.

7.8

CVSS3.1

CVE-2023-52916 - media: aspeed: Fix memory overwrite if timing is 1600x900

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: Fix memory overwrite if timing is 1600x900 When capturing 1600x900, system could crash when system memory usage is tight. The way to reproduce this issue: 1. Use 1600x900 to display on host 2. Mount ISO through 'V…

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

8.8

CVSS3.1

CVE-2024-44739 -

Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:21 p.m.

9.8

CVSS3.1

CVE-2024-44839 -

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 2:03 p.m.
Total resulsts: 348395
Page 8568 of 34,840
Β« previous page Β» next page
Filters