5.5

CVSS3.1

CVE-2024-36055 -

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via the MmMapIoSpace API (IOCTL 0x9c40a4f8, 0x9c40a4e8, 0x9c40a4c0, 0x9c40a4c4, 0x9c40a4ec, and seven others), leading to a denial of service (BSOD).

πŸ“… Published: May 26, 2024, 10:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-36054 -

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) and IOCTL 0x9c406490 (via ZwMapViewOfSection).

πŸ“… Published: May 26, 2024, 10:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-5381 - itsourcecode Student Information Management System view.php sql injection

A vulnerability classified as critical was found in itsourcecode Student Information Management System 1.0. Affected by this vulnerability is an unknown functionality of the file view.php. The manipulation of the argument studentId leads to sql injection. The attack can be launched remotely. The ex…

πŸ“… Published: May 26, 2024, 10:31 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2024-5380 - jsy-1 short-url admin.php cross site scripting

A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.0 is able to address t…

πŸ“… Published: May 26, 2024, 10:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.0

CVE-2024-4286 - Improper Neutralization of Special Elements in mintplex-labs/anything-llm

Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the application's handling of user modifications by ma…

πŸ“… Published: May 26, 2024, 10:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-5379 - JFinalCMS template cross site scripting

A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may be initiated remotely. The exploit has been discl…

πŸ“… Published: May 26, 2024, 10 p.m. πŸ”„ Last Modified: June 5, 2025, 8:04 p.m.

7.4

CVSS3.1

CVE-2024-34454 -

Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature (and because * is accepted as a Common Name).

πŸ“… Published: May 26, 2024, 9:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-5378 - SourceCodester School Intramurals Student Attendance Management System manage_sy.php sql injection

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_sy.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remo…

πŸ“… Published: May 26, 2024, 9:31 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 1:30 p.m.

6.9

CVSS4.0

CVE-2024-5377 - SourceCodester Vehicle Management System newvehicle.php unrestricted upload

A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the file /newvehicle.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit ha…

πŸ“… Published: May 26, 2024, 9 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 1:57 p.m.

5.3

CVSS4.0

CVE-2024-5376 - Kashipara College Management System view_each_faculty.php cross site scripting

A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file view_each_faculty.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exp…

πŸ“… Published: May 26, 2024, 8:31 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 6:26 p.m.
Total resulsts: 349182
Page 9666 of 34,919
Β« previous page Β» next page
Filters