9.8

CVSS3.1

CVE-2024-38989 -

izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-41332 -

Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: Aug. 21, 2024, 6:53 p.m.

7.8

CVSS3.1

CVE-2023-50809 -

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution…

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2023-31315 - hw: amd: SMM Lock Bypass

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-40472 -

Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: Aug. 15, 2024, 1:25 p.m.

4

CVSS3.1

CVE-2024-39338 - axios: axios: Server-Side Request Forgery

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: Aug. 23, 2024, 6:35 p.m.

7.5

CVSS3.1

CVE-2024-37826 -

A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: June 6, 2025, 8:33 p.m.

9.8

CVSS3.1

CVE-2024-41476 -

AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: Oct. 17, 2025, 5:13 p.m.

9.8

CVSS3.1

CVE-2024-41577 -

An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2023-50810 -

In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow persistent arbitrary code execution with Linux kernel privileges. A failure to correctly handle the return value of the setenv command can be used t…

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8910 of 34,919
Β« previous page Β» next page
Filters