|
320101
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number
Check the fb_channel_number range to avoid the array out-of-bounds
r…
|
-
|
CVE-2024-46724
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320102
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix ucode out-of-bounds read warning
Clear warning that read ucode[] may out-of-bounds.
|
-
|
CVE-2024-46723
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320103
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix mc_data out-of-bounds read warning
Clear warning that read mc_data[i-1] may out-of-bounds.
|
-
|
CVE-2024-46722
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320104
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix dereference after null check
check the pointer hive before use.
|
-
|
CVE-2024-46720
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320105
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: Fix null pointer dereference in trace
ucsi_register_altmode checks IS_ERR for the alt pointer and treats
NULL a…
|
-
|
CVE-2024-46719
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320106
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Don't overmap identity VRAM mapping
Overmapping the identity VRAM mapping is triggering hardware bugs on
certain platform…
|
-
|
CVE-2024-46718
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320107
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: SHAMPO, Fix incorrect page release
Under the following conditions:
1) No skb created yet
2) header_size == 0 (no SHAMP…
|
-
|
CVE-2024-46717
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320108
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor
Remove list_del call in msgdma_chan_desc_cleanup, th…
|
-
|
CVE-2024-46716
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320109
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix possible NULL pointer dereference
profile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made
fr…
|
-
|
CVE-2024-46721
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320110
|
- |
-
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
driver: iio: add missing checks on iio_info's callback access
Some callbacks from iio_info structure are accessed without any che…
|
-
|
CVE-2024-46715
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320111
|
- |
-
|
-
|
-
|
OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the devi…
|
-
|
CVE-2024-43778
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320112
|
- |
-
|
-
|
-
|
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the d…
|
-
|
CVE-2024-41929
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320113
|
- |
-
|
-
|
-
|
SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database.
|
-
|
CVE-2024-42404
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320114
|
- |
-
|
-
|
-
|
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.
|
-
|
CVE-2024-45679
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320115
|
- |
-
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a …
|
CWE-89
SQL Injection
|
CVE-2024-43969
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320116
|
- |
-
|
-
|
-
|
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medi…
|
-
|
CVE-2024-8905
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320117
|
- |
-
|
-
|
-
|
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
-
|
CVE-2024-8904
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320118
|
- |
-
|
-
|
-
|
Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages r…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-46982
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320119
|
- |
-
|
-
|
-
|
Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. …
|
CWE-79
Cross-site Scripting
|
CVE-2024-45812
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320120
|
- |
-
|
-
|
-
|
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2024-45811
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320121
|
- |
-
|
-
|
-
|
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulnerable to multiple Poisoned Pipeline Execution (PPE…
|
CWE-94 CWE-20 CWE-78
Code Injection Improper Input Validation OS Command
|
CVE-2024-45798
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320122
|
- |
-
|
-
|
-
|
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a …
|
-
|
CVE-2024-42503
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320123
|
- |
-
|
-
|
-
|
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underly…
|
-
|
CVE-2024-42502
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320124
|
- |
-
|
-
|
-
|
An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system…
|
-
|
CVE-2024-42501
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320125
|
- |
-
|
-
|
-
|
A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-base…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2024-8939
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320126
|
- |
-
|
-
|
-
|
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.
|
CWE-617
Reachable Assertion
|
CVE-2024-8768
|
2024-09-20 21:30 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320127
|
- |
-
|
-
|
-
|
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
|
-
|
CVE-2024-38860
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320128
|
- |
-
|
-
|
-
|
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-21743
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320129
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2024-7873
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320130
|
- |
-
|
-
|
-
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
|
-
|
CVE-2024-46362
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320131
|
- |
-
|
-
|
-
|
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename
|
-
|
CVE-2024-46085
|
2024-09-20 21:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320132
|
- |
-
|
-
|
-
|
Rejected reason: DoS issues, or unexploitable crashes, are out of scope for vulnerabilities.
|
-
|
CVE-2023-36268
|
2024-09-20 18:15 |
2024-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320133
|
- |
-
|
-
|
-
|
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
|
-
|
CVE-2024-8963
|
2024-09-20 10:00 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320134
|
9.8 |
CRITICAL
Network
|
tenda
|
o6_firmware
|
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46049
|
2024-09-20 09:39 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320135
|
9.8 |
CRITICAL
Network
|
tenda
|
fh451_firmware
|
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
|
CWE-77
Command Injection
|
CVE-2024-46048
|
2024-09-20 09:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320136
|
7.5 |
HIGH
Network
|
tenda
|
fh451_firmware
|
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46047
|
2024-09-20 09:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320137
|
9.8 |
CRITICAL
Network
|
tenda
|
fh451_firmware
|
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46046
|
2024-09-20 09:35 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320138
|
9.8 |
CRITICAL
Network
|
tenda
|
ch22_firmware
|
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46044
|
2024-09-20 09:34 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320139
|
5.9 |
MEDIUM
Network
|
consensys
|
gnark-crypto
|
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property…
|
NVD-CWE-noinfo
|
CVE-2024-45040
|
2024-09-20 09:13 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320140
|
6.2 |
MEDIUM
Local
|
consensys
|
gnark-crypto
|
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover …
|
NVD-CWE-noinfo
|
CVE-2024-45039
|
2024-09-20 09:12 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320141
|
8.8 |
HIGH
Network
|
thimpress
|
wp_events_manager
|
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user su…
|
CWE-89
SQL Injection
|
CVE-2024-7717
|
2024-09-20 09:08 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320142
|
5.3 |
MEDIUM
Network
|
wpcerber
|
cerber_security_antispam_\&_malware_scan
|
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it …
|
NVD-CWE-noinfo
|
CVE-2022-4100
|
2024-09-20 09:08 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320143
|
5.3 |
MEDIUM
Network
|
youtag
|
ip-vault-wp-firewall
|
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address informatio…
|
NVD-CWE-Other
|
CVE-2022-4536
|
2024-09-20 09:04 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320144
|
6.3 |
MEDIUM
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
|
CWE-787
Out-of-bounds Write
|
CVE-2024-38207
|
2024-09-20 07:15 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320145
|
7.8 |
HIGH
Local
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
CWE-125
Out-of-bounds Read
|
CVE-2024-38210
|
2024-09-20 07:15 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320146
|
7.8 |
HIGH
Local
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
CWE-843
Type Confusion
|
CVE-2024-38209
|
2024-09-20 07:15 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320147
|
6.1 |
MEDIUM
Network
|
microsoft
|
edge
|
Microsoft Edge for Android Spoofing Vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2024-38208
|
2024-09-20 07:15 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320148
|
5.4 |
MEDIUM
Network
|
wpbeaveraddons
|
powerpack_lite_for_beaver_builder
|
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.8.3.5 due to insufficien…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7895
|
2024-09-20 07:13 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320149
|
5.4 |
MEDIUM
Network
|
funnelkit
|
funnel_builder
|
The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html' filter to globally…
|
CWE-79
Cross-site Scripting
|
CVE-2024-1056
|
2024-09-20 07:06 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320150
|
9.8 |
CRITICAL
Network
|
geeeeeeeek
|
dingfanzu
|
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.…
|
CWE-89
SQL Injection
|
CVE-2024-8302
|
2024-09-20 06:55 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|