6.1

CVSS3.1

CVE-2024-34312 -

Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

4.7

CVSS3.1

CVE-2024-34030 - PCI: of_property: Return error for int_map allocation failure

In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocation failure Return -ENOMEM from of_pci_prop_intr_map() if kcalloc() fails to prevent a NULL pointer dereference in this case. [bhelgaas: commit log]

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:05 a.m.

9.8

CVSS3.1

CVE-2024-33879 -

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:17 a.m.

7

CVSS3.1

CVE-2024-34027 - f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock It needs to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock to avoid racing with checkpoint, otherwise, filesystem metadata including bl…

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:05 a.m.

9.8

CVSS3.1

CVE-2024-38902 -

H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 4:21 p.m.

7.3

CVSS3.1

CVE-2024-36683 -

SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via the ProductsAlertAjaxProcessModuleFrontController::initContent method.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-38895 -

WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: June 6, 2025, 5:13 p.m.

5.5

CVSS3.1

CVE-2024-37021 - fpga: manager: add owner module and take its refcount

In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga manager assumes that the low-level module registers a driver for the parent device and uses its owner pointer to take the module's refco…

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

5.3

CVSS3.1

CVE-2024-33881 -

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:17 a.m.

7.4

CVSS3.1

CVE-2025-0306 - Ruby: openssl: ruby marvin attack

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

πŸ“… Published: June 24, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9352 of 34,919
Β« previous page Β» next page
Filters