8.4

CVSS3.1

CVE-2024-41928 - bhyve(8) privileged guest escape via TPM device passthrough

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve proces…

πŸ“… Published: Sept. 5, 2024, 3:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2024-45288 - Multiple vulnerabilities in libnv

A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

πŸ“… Published: Sept. 5, 2024, 3:18 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-45287 - Multiple vulnerabilities in libnv

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.

πŸ“… Published: Sept. 5, 2024, 3:18 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:37 a.m.

8.1

CVSS3.1

CVE-2024-7627 - Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attacker…

πŸ“… Published: Sept. 5, 2024, 2:04 a.m. πŸ”„ Last Modified: Sept. 11, 2024, 4:31 p.m.

5.7

CVSS3.1

CVE-2024-8445 - 389-ds-base: server crash while modifying `userpassword` using malformed input (incomplete fix for …

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-45158 -

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This n…

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: May 16, 2025, 8:17 p.m.

5.1

CVSS3.1

CVE-2024-45157 -

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_R…

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-45171 -

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files …

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:35 p.m.

4.7

CVSS3.1

CVE-2023-51712 -

An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-44587 -

itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.

πŸ“… Published: Sept. 5, 2024, midnight πŸ”„ Last Modified: May 14, 2025, 3:40 p.m.
Total resulsts: 349182
Page 8654 of 34,919
Β« previous page Β» next page
Filters