261
|
- |
|
-
|
-
|
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" G…
New
|
-
|
CVE-2024-57687
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
262
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.
New
|
-
|
CVE-2024-51229
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263
|
- |
|
-
|
-
|
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQ…
New
|
-
|
CVE-2024-54762
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264
|
- |
|
-
|
-
|
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
New
|
-
|
CVE-2024-54761
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ar8035_firmware c-v2x_9150_firmware csrb31024_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware msm8996au_firmware qam8295p_firmware qca63…
|
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33067
|
2025-01-11 00:39 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266
|
5.5 |
MEDIUM
Local
|
qualcomm
|
qam8255p_firmware qam8295p_firmware qam8650p_firmware qam8775p_firmware qamsrv1h_firmware qca6595_firmware qca6595au_firmware qca6696_firmware qca6698aq_firmware sa8255p_fi…
|
information disclosure while invoking the mailbox read API.
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-43063
|
2025-01-11 00:37 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267
|
7.8 |
HIGH
Local
|
google
|
android
|
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional e…
Update
|
NVD-CWE-noinfo
|
CVE-2023-35685
|
2025-01-11 00:30 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268
|
- |
|
-
|
-
|
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.
New
|
-
|
CVE-2025-22946
|
2025-01-11 00:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269
|
- |
|
-
|
-
|
A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "page…
New
|
-
|
CVE-2024-57686
|
2025-01-11 00:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270
|
- |
|
-
|
-
|
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
New
|
-
|
CVE-2024-57822
|
2025-01-11 00:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|