7.0

CVSS3.1

CVE-2024-43883 - usb: vhci-hcd: Do not drop references before new references are gained

In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. This strictly speaking closes ZDI-CAN-…

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.

9.8

CVSS3.1

CVE-2024-42531 -

Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish…

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-44381 -

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Aug. 26, 2024, 1:55 p.m.

8

CVSS3.1

CVE-2024-42915 -

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-44387 -

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Dec. 13, 2024, 3:15 p.m.

9.4

CVSS3.1

CVE-2024-42764 -

Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 1:48 p.m.

8.8

CVSS3.1

CVE-2024-39841 -

A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: May 9, 2025, 2:12 p.m.

8.8

CVSS3.1

CVE-2024-44382 -

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Aug. 26, 2024, 1:58 p.m.

4.3

CVSS3.1

CVE-2024-43031 -

autMan v2.9.6 was discovered to contain an access control issue.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Sept. 3, 2025, 7:16 p.m.

5.4

CVSS3.1

CVE-2024-42918 -

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 4:15 p.m.
Total resulsts: 349182
Page 8752 of 34,919
Β« previous page Β» next page
Filters