6.1

CVSS3.1

CVE-2024-51434 -

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-48951 -

An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:36 p.m.

5.5

CVSS3.1

CVE-2024-50147 - net/mlx5: Fix command bitmask initialization

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix command bitmask initialization Command bitmask have a dedicated bit for MANAGE_PAGES command, this bit isn't Initialize during command bitmask Initialization, only during MANAGE_PAGES. In addition, mlx5_cmd_trigger…

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.4

CVSS3.1

CVE-2020-11918 -

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:15 p.m.

9.8

CVSS3.1

CVE-2024-50766 -

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 7:30 p.m.

8.8

CVSS3.1

CVE-2019-20458 -

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the …

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-36063 -

The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component.

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-48954 -

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:42 p.m.

5.5

CVSS3.1

CVE-2024-50142 - xfrm: validate new SA's prefixlen using SA family when sel.family is unset

In the Linux kernel, the following vulnerability has been resolved: xfrm: validate new SA's prefixlen using SA family when sel.family is unset This expands the validation introduced in commit 07bf7908950a ("xfrm: Validate address prefix lengths in the xfrm selector.") syzbot created an SA with …

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

7.8

CVSS3.1

CVE-2024-50150 - usb: typec: altmode should keep reference to parent

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent The altmode device release refers to its parent device, but without keeping a reference to it. When registering the altmode, get a reference to the parent and put it in the rel…

πŸ“… Published: Nov. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.
Total resulsts: 344980
Page 7579 of 34,498
Β« previous page Β» next page
Filters