5.5

CVSS3.1

CVE-2024-50081 - blk-mq: setup queue ->tag_set before initializing hctx

In the Linux kernel, the following vulnerability has been resolved: blk-mq: setup queue ->tag_set before initializing hctx Commit 7b815817aa58 ("blk-mq: add helper for checking if one CPU is mapped to specified hctx") needs to check queue mapping via tag set in hctx's cpuhp handler. However, q->โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 11, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-51075 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2024, 1:41 p.m.

4.8

CVSS3.1

CVE-2024-48461 -

Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2024-51568 -

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 4:17 p.m.

5.3

CVSS3.1

CVE-2024-48572 -

A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs due to insufficiently validated user input being processed as a regular expression, which is then matched against email โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 8:23 p.m.

8.1

CVSS3.1

CVE-2024-48955 -

Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-50083 - tcp: fix mptcp DSS corruption due to large pmtu xmit

In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger a DSS corruption: TCP: request_sock_subflow_v4: Possible SYN flooding on port [::]:20002. Sending cookies. ------------[ cut here ]----------โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

7.8

CVSS3.1

CVE-2024-50071 - pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func()

In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func() 'new_map' is allocated using devm_* which takes care of freeing the allocated data on device removal, call to .dt_free_map = pinconf_generic_dt_free_map โ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

9.8

CVSS3.1

CVE-2024-44081 -

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: July 10, 2025, 7:34 p.m.

6.1

CVSS3.1

CVE-2024-51076 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.

๐Ÿ“… Published: Oct. 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2024, 1:41 p.m.
Total resulsts: 345149
Page 7704 of 34,515
ยซ previous page ยป next page
Filters