6.9

CVSS4.0

CVE-2025-0458 - Virtual Computer Vysual RH Solution Login Panel index.php cross site scripting

A vulnerability classified as problematic was found in Virtual Computer Vysual RH Solution 2024.12.1. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Panel. The manipulation of the argument page leads to cross site scripting. The attack can b…

πŸ“… Published: Jan. 14, 2025, 3:31 p.m. πŸ”„ Last Modified: Jan. 14, 2025, 4:43 p.m.

5.6

CVSS3.1

CVE-2024-12747 - Rsync: race condition in rsync handling symbolic links

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass t…

πŸ“… Published: Jan. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Jan. 28, 2026, 6:57 p.m.

9.8

CVSS3.1

CVE-2024-12084 - Rsync: heap buffer overflow in rsync due to improper checksum length handling

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

πŸ“… Published: Jan. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2024-12088 - Rsync: --safe-links option bypass leads to path traversal

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the…

πŸ“… Published: Jan. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Jan. 28, 2026, 6:57 p.m.

6.5

CVSS3.1

CVE-2024-12087 - Rsync: path traversal vulnerability in rsync

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper s…

πŸ“… Published: Jan. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Jan. 28, 2026, 6:57 p.m.

7.5

CVSS3.1

CVE-2024-12085 - Rsync: info leak via uninitialized stack contents

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

πŸ“… Published: Jan. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.1

CVSS3.1

CVE-2024-12086 - Rsync: rsync server leaks arbitrary client files

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with…

πŸ“… Published: Jan. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Jan. 28, 2026, 6:57 p.m.

7.5

CVSS3.1

CVE-2024-42444 - TOCTOU Race Condition between DMA and SMM

APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of arbitrary code on the target device.

πŸ“… Published: Jan. 14, 2025, 3 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 2:33 p.m.

10

CVSS3.1

CVE-2024-34166 -

An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.

πŸ“… Published: Jan. 14, 2025, 2:21 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:46 p.m.

9.6

CVSS3.1

CVE-2024-39363 -

A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vuln…

πŸ“… Published: Jan. 14, 2025, 2:21 p.m. πŸ”„ Last Modified: Jan. 14, 2025, 4:15 p.m.
Total resulsts: 343924
Page 6614 of 34,393
Β« previous page Β» next page
Filters