3.9

CVSS3.1

CVE-2024-45617 - Libopensc: uninitialized values after incorrect or missing checking return values of functions in l…

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unex…

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:29 a.m.

9.8

CVSS3.1

CVE-2024-45622 -

ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-45621 -

The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2024-44947 - fuse: Initialize beyond-EOF page contents before setting uptodate

In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page contents). So fuse_notify_store() must…

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

3.9

CVSS3.1

CVE-2024-45618 - Libopensc: uninitialized values after incorrect or missing checking return values of functions in p…

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have…

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:29 a.m.

3.9

CVSS3.1

CVE-2024-45615 - Libopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:29 a.m.

4.3

CVSS3.1

CVE-2024-45619 - Libopensc: incorrect handling length of buffers or files in libopensc

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer c…

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:29 a.m.

4.3

CVSS3.1

CVE-2024-45270 -

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPres…

πŸ“… Published: Sept. 1, 2024, 11:55 p.m. πŸ”„ Last Modified: March 13, 2025, 8:15 p.m.

4.3

CVSS3.1

CVE-2024-45269 -

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the Word…

πŸ“… Published: Sept. 1, 2024, 11:55 p.m. πŸ”„ Last Modified: March 13, 2025, 4:15 p.m.

5.3

CVSS4.0

CVE-2024-8370 - Grocy SVG File Upload recipepictures cross site scripting

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File Upload Handler. The manipulation of the argument force_serve_as with the input picture' leads to cross site scripting. T…

πŸ“… Published: Sept. 1, 2024, 10 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:59 p.m.
Total resulsts: 349182
Page 8688 of 34,919
Β« previous page Β» next page
Filters