6.9

CVSS4.0

CVE-2024-6213 - SourceCodester Food Ordering Management System Login Panel login.php sql injection

A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file login.php of the component Login Panel. The manipulation of the argument username leads to sql injection. It is possible to initiate th…

πŸ“… Published: June 21, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6212 - SourceCodester Simple Student Attendance System student_form.php get_student cross site scripting

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. Th…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

0.0

CVE-2024-39152 -

DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-6655. Reason: This record is a reservation duplicate of CVE-2024-6655. Notes: All CVE users should reference CVE-2024-6655 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: July 18, 2024, 7:15 p.m.

4.8

CVSS3.1

CVE-2022-42974 -

In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) attack on /file.bootloader.upload.html. The application fails to sanitize the parameter filename, in a POST request to /file.bootloader.upload.html for a system…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 7:25 a.m.

5.5

CVSS3.1

CVE-2024-38390 - drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails

In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails Calling a6xx_destroy() before adreno_gpu_init() leads to a null pointer dereference on: msm_gpu_cleanup() : platform_set_drvdata(gpu->pdev, NULL); as gpu->pd…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 12:56 p.m.

3.3

CVSS3.1

CVE-2024-38388 - ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup Use the control private_free callback to free the associated data block. This ensures that the memory won't leak, whatever way the control gets destroyed. The original i…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:13 a.m.

7.1

CVSS3.1

CVE-2024-38381 - nfc: nci: Fix uninit-value in nci_rx_work

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header size, payload size and total packet size b…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

6.1

CVSS3.1

CVE-2024-37654 -

An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD befo…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: July 12, 2025, 3:42 p.m.

7.1

CVSS3.1

CVE-2024-38659 - enic: Validate length of nl attributes in enic_set_vf_port

In the Linux kernel, the following vulnerability has been resolved: enic: Validate length of nl attributes in enic_set_vf_port enic_set_vf_port assumes that the nl attribute IFLA_PORT_PROFILE is of length PORT_PROFILE_MAX and that the nl attributes IFLA_PORT_INSTANCE_UUID, IFLA_PORT_HOST_UUID are…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

5.5

CVSS3.1

CVE-2024-38636 - f2fs: multidev: fix to recognize valid zero block address

In the Linux kernel, the following vulnerability has been resolved: f2fs: multidev: fix to recognize valid zero block address As reported by Yi Zhang in mailing list [1], kernel warning was catched during zbd/010 test as below: ./check zbd/010 zbd/010 (test gap zone support with F2FS) …

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Oct. 3, 2025, 2:55 p.m.
Total resulsts: 342218
Page 8670 of 34,222
Β« previous page Β» next page
Filters