8.8

CVSS3.1

CVE-2024-7435 - Attire <= 2.0.6 - Authenticated (Contributor+) PHP Object Injection

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present…

πŸ“… Published: Aug. 31, 2024, 2:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:32 p.m.

8.1

CVSS3.1

CVE-2024-39747 - IBM Sterling Connect:Direct Web Services information disclosure

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

πŸ“… Published: Aug. 31, 2024, 1:01 a.m. πŸ”„ Last Modified: Sept. 16, 2024, 5:13 p.m.

7.8

CVSS3.1

CVE-2024-44945 - netfilter: nfnetlink: Initialise extack before use in ACKs

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.

πŸ“… Published: Aug. 31, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:29 a.m.

5.5

CVSS3.1

CVE-2024-44946 - kcm: Serialise kcm_sendmsg() for the same socket.

In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario is 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb. 2. Thread A resumes building skb from kcm->seq_sk…

πŸ“… Published: Aug. 31, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

4.4

CVSS3.1

CVE-2024-8006 - NULL pointer dereference in libpcap before 1.10.5 with remote packet capture support

Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs_ex(). One of the function arguments can be a filesystem path, which normally means a directory wit…

πŸ“… Published: Aug. 30, 2024, 11:53 p.m. πŸ”„ Last Modified: Sept. 19, 2024, 5:46 p.m.

5.3

CVSS3.1

CVE-2024-45304 - OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ow…

Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's intention of leaving the contract without an owner. It introduces a security risk where an unintended…

πŸ“… Published: Aug. 30, 2024, 11:51 p.m. πŸ”„ Last Modified: Sept. 19, 2024, 5:26 p.m.

4.4

CVSS3.1

CVE-2023-7256 - Double-free in libpcap before 1.10.5 with remote packet capture support.

In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns. This…

πŸ“… Published: Aug. 30, 2024, 11:44 p.m. πŸ”„ Last Modified: Sept. 19, 2024, 5:53 p.m.

7.3

CVSS3.1

CVE-2024-6586 -

Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST request to /api/v1/d…

πŸ“… Published: Aug. 30, 2024, 10:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-6585 -

Multiple stored cross-site scripting (β€œXSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vul…

πŸ“… Published: Aug. 30, 2024, 10:17 p.m. πŸ”„ Last Modified: Sept. 3, 2024, 3:35 p.m.

5.3

CVSS4.0

CVE-2024-8348 - SourceCodester Computer Laboratory Management System Master.php delete_category sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The at…

πŸ“… Published: Aug. 30, 2024, 9:31 p.m. πŸ”„ Last Modified: Sept. 4, 2024, 4:43 p.m.
Total resulsts: 349182
Page 8691 of 34,919
Β« previous page Β» next page
Filters