9.8

CVSS3.1

CVE-2021-47378 - nvme-rdma: destroy cm id before destroy qp to avoid use after free

In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid use after free We should always destroy cm_id before destroy qp to avoid to get cma event after qp was destroyed, which may lead to use after free. In RDMA connection establishmโ€ฆ

๐Ÿ“… Published: May 21, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 11:37 a.m.

5.5

CVSS3.1

CVE-2021-47304 - tcp: fix tcp_init_transfer() to not reset icsk_ca_initialized

In the Linux kernel, the following vulnerability has been resolved: tcp: fix tcp_init_transfer() to not reset icsk_ca_initialized This commit fixes a bug (found by syzkaller) that could cause spurious double-initializations for congestion control modules, which could cause memory leaks or other pโ€ฆ

๐Ÿ“… Published: May 21, 2024, midnight ๐Ÿ”„ Last Modified: May 12, 2025, 8 p.m.

5.5

CVSS3.1

CVE-2021-47331 - usb: common: usb-conn-gpio: fix NULL pointer dereference of charger

In the Linux kernel, the following vulnerability has been resolved: usb: common: usb-conn-gpio: fix NULL pointer dereference of charger When power on system with OTG cable, IDDIG's interrupt arises before the charger registration, it will cause a NULL pointer dereference, fix the issue by registeโ€ฆ

๐Ÿ“… Published: May 21, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 11:36 a.m.

5.3

CVSS4.0

CVE-2024-5145 - SourceCodester Vehicle Management System HTTP POST Request newdriver.php unrestricted upload

A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /newdriver.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The attacโ€ฆ

๐Ÿ“… Published: May 20, 2024, 10:31 p.m. ๐Ÿ”„ Last Modified: Feb. 10, 2025, 1:57 p.m.

7.1

CVSS3.1

CVE-2024-34710 - Wiki.js Stored XSS through Client Side Template Injection

Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the content section of pages that would execute once a victim loads the page that contains the payload. This was possible through the injection ofโ€ฆ

๐Ÿ“… Published: May 20, 2024, 9:59 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2024-4985 -

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain access to a user with โ€ฆ

๐Ÿ“… Published: May 20, 2024, 9:17 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 8:53 p.m.

5.3

CVSS3.1

CVE-2024-35194 - Stacklok Minder vulnerable to denial of service from maliciously crafted templates

Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaustion that can be triggered from maliciously created templates. Minder engine uses templating to generate strings for various use cases such as URLs, meโ€ฆ

๐Ÿ“… Published: May 20, 2024, 8:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-35192 - Trivy possibly leaks registry credential when scanning images from malicious registries

Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Containโ€ฆ

๐Ÿ“… Published: May 20, 2024, 8:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-33900 -

KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

๐Ÿ“… Published: May 20, 2024, 8:29 p.m. ๐Ÿ”„ Last Modified: June 13, 2025, 4:16 p.m.

4.4

CVSS3.1

CVE-2024-35191 - verbb/formie Server-Side Template Injection for variable-enabled settings

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or renderingโ€ฆ

๐Ÿ“… Published: May 20, 2024, 8:26 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 2:16 p.m.
Total resulsts: 349182
Page 9761 of 34,919
ยซ previous page ยป next page
Filters