5.3

CVSS4.0

CVE-2024-11127 - code-projects Job Recruitment admin.php sql injection

A vulnerability was found in code-projects Job Recruitment up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin.php. The manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit …

πŸ“… Published: Nov. 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 5:29 p.m.

6.5

CVSS3.1

CVE-2024-51566 - bhyve(8) NVMe driver to guest-induced infinite loops.

The NVMe driver queue processing is vulernable to guest-induced infinite loops.

πŸ“… Published: Nov. 12, 2024, 2:58 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

6.5

CVSS3.1

CVE-2024-51565 - bhyve(8) hda driver buffer over-read

The hda driver is vulnerable to a buffer over-read from a guest-controlled value.

πŸ“… Published: Nov. 12, 2024, 2:53 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

7

CVSS4.0

CVE-2024-37365 - FactoryTalk View ME Remote Code Execution Vulnerability via Project Save Path

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate…

πŸ“… Published: Nov. 12, 2024, 2:52 p.m. πŸ”„ Last Modified: Nov. 12, 2024, 7:04 p.m.

7.5

CVSS3.1

CVE-2024-51564 - bhyve(8) infinite loop in the hda audio driver

A guest can trigger an infinite loop in the hda audio driver.

πŸ“… Published: Nov. 12, 2024, 2:51 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

6.5

CVSS3.1

CVE-2024-51563 - bhyve(8) virtio_vq_recordon time-of-check to time-of-use race

The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.

πŸ“… Published: Nov. 12, 2024, 2:47 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

9.3

CVSS4.0

CVE-2024-8074 - Sensetive Data Exposure in Nomysoft Informatics' Nomysem

Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users.This issue affects Nomysem: before 13.10.2024.

πŸ“… Published: Nov. 12, 2024, 2:45 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 7:21 p.m.

6.5

CVSS3.1

CVE-2024-51562 - bhyve(8) nvme_opc_get_log_page buffer over-read

The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.

πŸ“… Published: Nov. 12, 2024, 2:44 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

8.5

CVSS3.1

CVE-2024-50386 - Apache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instances. Due to missing validation checks for KVM-compatible templates in CloudStack 4.0.0 through 4.18.2.4 and 4.19.0.0 through 4.19.1.2, an attacker tha…

πŸ“… Published: Nov. 12, 2024, 2:34 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 6:23 p.m.

2.3

CVSS4.0

CVE-2024-11126 - Digistar AG-30 Plus Login Page excessive authentication

A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The complexity of an attack is rather high. The exploitabil…

πŸ“… Published: Nov. 12, 2024, 2:31 p.m. πŸ”„ Last Modified: Nov. 12, 2024, 8:13 p.m.
Total resulsts: 343757
Page 7391 of 34,376
Β« previous page Β» next page
Filters