5.9

CVSS3.1

CVE-2025-2312 - cifs.upcall makes an upcall to the wrong namespace in containerized environments

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-51135 -

An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-51189 -

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 1, 2025, 6:21 p.m.

4.8

CVSS3.1

CVE-2024-51054 -

A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: March 27, 2025, 5:35 p.m.

8.1

CVSS3.1

CVE-2024-46963 -

The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-48939 -

Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-25255 -

Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-49394 - Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2025, 6:57 a.m.

9.8

CVSS3.1

CVE-2024-52533 - glib: buffer overflow in set_connect_msg()

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 1:23 a.m.

7.5

CVSS3.1

CVE-2024-25253 -

Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345215
Page 7554 of 34,522
ยซ previous page ยป next page
Filters