8.8

CVSS3.1

CVE-2024-53940 -

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the ping utility, enabling…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Dec. 3, 2024, 7:15 p.m.

7.5

CVSS3.1

CVE-2024-31669 -

rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: July 2, 2025, 8:36 p.m.

9.8

CVSS3.1

CVE-2024-53477 -

JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 1:44 p.m.

7.5

CVSS3.1

CVE-2024-53605 -

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Dec. 4, 2024, 6:15 p.m.

5.5

CVSS3.1

CVE-2024-53115 - drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle The 'vmw_user_object_buffer' function may return NULL with incorrect inputs. To avoid possible null pointer dereference, add a check whether the 'bo' is NU…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

7

CVSS3.1

CVE-2024-39343 -

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mobility Management) module, which can lead to Denial of Servic…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: July 1, 2025, 3 p.m.

5.5

CVSS3.1

CVE-2024-53109 - nommu: pass NULL argument to vma_iter_prealloc()

In the Linux kernel, the following vulnerability has been resolved: nommu: pass NULL argument to vma_iter_prealloc() When deleting a vma entry from a maple tree, it has to pass NULL to vma_iter_prealloc() in order to calculate internal state of the tree, but it passed a wrong argument. As a resu…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

5.4

CVSS3.1

CVE-2024-53364 -

A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: April 7, 2025, 3:04 p.m.

5.5

CVSS3.1

CVE-2024-53111 - mm/mremap: fix address wraparound in move_page_tables()

In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix address wraparound in move_page_tables() On 32-bit platforms, it is possible for the expression `len + old_addr < old_end` to be false-positive if `len + old_addr` wraps around. `old_addr` is the cursor in the old…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

8.8

CVSS3.1

CVE-2024-53938 -

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achieve full control over the router remotely wi…

πŸ“… Published: Dec. 2, 2024, midnight πŸ”„ Last Modified: Dec. 3, 2024, 7:15 p.m.
Total resulsts: 344009
Page 7145 of 34,401
Β« previous page Β» next page
Filters