7.8

CVSS3.1

CVE-2024-31333 -

In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 15, 2024, 9:56 p.m. πŸ”„ Last Modified: Dec. 17, 2024, 6:13 p.m.

6.9

CVSS4.0

CVE-2024-7842 - SourceCodester Online Graduate Tracer System export_it.php information disclosure

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the file /tracking/admin/export_it.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The…

πŸ“… Published: Aug. 15, 2024, 9:31 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 5:37 p.m.

5.3

CVSS4.0

CVE-2024-7841 - SourceCodester Clinics Patient Management System check_user_name.php sql injection

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation of the argument user_name leads to sql injection. The attack can be initiated remotely. The e…

πŸ“… Published: Aug. 15, 2024, 9:31 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 7:32 p.m.

6.9

CVSS4.0

CVE-2024-7839 - itsourcecode Billing System addbill.php sql injection

A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the pu…

πŸ“… Published: Aug. 15, 2024, 9 p.m. πŸ”„ Last Modified: Aug. 19, 2024, 9:18 p.m.

7.5

CVSS3.1

CVE-2024-43367 - Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects

Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0.19.0, a wrong assumption made when handling ECMAScript's `AsyncGenerator` operations can cause an uncaught exception on certain scripts. Boa's implementation of `AsyncGenerator` …

πŸ“… Published: Aug. 15, 2024, 8:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-42488 - Cilium agent's race condition may lead to policy bypass for Host Firewall policy

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies inte…

πŸ“… Published: Aug. 15, 2024, 8:36 p.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:49 p.m.

4

CVSS3.1

CVE-2024-42487 - Cilium's Gateway API route matching order contradicts specification

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification. In particular, requ…

πŸ“… Published: Aug. 15, 2024, 8:26 p.m. πŸ”„ Last Modified: Sept. 30, 2024, 6:31 p.m.

2.1

CVSS4.0

CVE-2024-7868 - Uninitialized variable in Xpdf 4.05 due to invalid JPEG header

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.

πŸ“… Published: Aug. 15, 2024, 8:22 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 11:15 p.m.

7.5

CVSS3.1

CVE-2024-43366 - zkvyper ignored loop range bounds

zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much more late exit condition. It leads to a loss of funds or other unwanted behavior if the loop body contains it. However, mor…

πŸ“… Published: Aug. 15, 2024, 8:11 p.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:08 p.m.

8.5

CVSS4.0

CVE-2024-6456 - SQL Injection vulnerability in AVEVA Historian Server

AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.

πŸ“… Published: Aug. 15, 2024, 8:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8835 of 34,919
Β« previous page Β» next page
Filters