4.1

CVSS3.1

CVE-2024-0134 - nvidia-container-toolkit: specially-crafted container image can lead to the creation of unauthorize…

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerab…

πŸ“… Published: Nov. 5, 2024, 6:37 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 3:53 p.m.

7.2

CVSS3.1

CVE-2024-49774 - ModuleScanner flaws in SuiteCRM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks can be bypassed with some syntax constructions. SuiteCRM uses token_get_all to p…

πŸ“… Published: Nov. 5, 2024, 6:37 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 8:40 p.m.

5.3

CVSS3.1

CVE-2024-49773 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SuiteCRM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is used to build SQL query. `current_post` parameter in `export` entry point can be ab…

πŸ“… Published: Nov. 5, 2024, 6:35 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 8:29 p.m.

8.8

CVSS3.1

CVE-2024-49772 - Authenticated SQL injection in AM_ProjectTemplates controller in SuiteCRM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can leak all data in database. This issue has been a…

πŸ“… Published: Nov. 5, 2024, 6:31 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 8:19 p.m.

5.5

CVSS3.1

CVE-2024-49377 - Jinja2 Templates are vulnerable to XSS attacks due to their configuration in OctoPrint

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone application key confirmation dialog. An attacker who successfully talked a victim into clicking on …

πŸ“… Published: Nov. 5, 2024, 6:20 p.m. πŸ”„ Last Modified: Dec. 18, 2024, 4:31 p.m.

5.3

CVSS3.1

CVE-2024-51493 - API key access in settings without reauthentication in OctoPrint

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to retrieve/recreate/delete the user's…

πŸ“… Published: Nov. 5, 2024, 6:17 p.m. πŸ”„ Last Modified: Dec. 18, 2024, 4:34 p.m.

4.3

CVSS3.1

CVE-2024-51740 - SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manager has been fixed to only instantiate classes derived from it. This issue has been addressed in versi…

πŸ“… Published: Nov. 5, 2024, 6:13 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 9:09 p.m.

7.5

CVSS3.1

CVE-2024-51739 - Users enumeration allowed through Rest API in Combodo iTop

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This fix is included in ver…

πŸ“… Published: Nov. 5, 2024, 6:11 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 3:56 p.m.

7.8

CVSS3.1

CVE-2024-50124 - Bluetooth: ISO: Fix UAF on iso_sock_timeout

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix UAF on iso_sock_timeout conn->sk maybe have been unlinked/freed while waiting for iso_conn_lock so this checks if the conn->sk is still valid by checking if it part of iso_sk_list.

πŸ“… Published: Nov. 5, 2024, 5:10 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-50118 - btrfs: reject ro->rw reconfiguration if there are hard ro requirements

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject ro->rw reconfiguration if there are hard ro requirements [BUG] Syzbot reports the following crash: BTRFS info (device loop0 state MCS): disabling free space tree BTRFS info (device loop0 state MCS): clearing co…

πŸ“… Published: Nov. 5, 2024, 5:10 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.
Total resulsts: 346560
Page 7750 of 34,656
Β« previous page Β» next page
Filters