5.5
CVE-2024-43885 - kernel: btrfs: fix double inode unlock for direct IO sync writes
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
9.8
CVE-2024-41444 -
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
9.8
CVE-2024-44551 -
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
7.5
CVE-2024-45241 -
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
6.1
CVE-2024-39097 -
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
5.5
CVE-2024-43909 - drm/amdgpu/pm: Fix the null pointer dereference for smu7
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm: Fix the null pointer dereference for smu7 optimize the code to avoid pass a null pointer (hwmgr->backend) to function smu7_update_edc_leakage_table.
7.8
CVE-2024-44940 - fou: remove warn in gue_gro_receive on unsupported protocol
In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is not known or does not have a GRO handler. Such a packet is easily constructed. Syzbot generates thβ¦
4.1
CVE-2024-42906 -
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
8.8
CVE-2024-44553 -
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
9.8
CVE-2024-41285 -
A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.