611
|
9.8 |
CRITICAL
Network
doverfuelingsolutions
|
progauge_maglink_lx_console_firmware progauge_maglink_lx4_console_firmware
|
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE
UTILITY sub-menu can allow a remote attacker to inject arbitrary
commands.
Update
|
CWE-77
Command Injection
|
CVE-2024-43693
|
2024-10-2 02:17 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
612
|
7.8 |
HIGH
Local
|
telerik
|
ui_for_wpf
|
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Update
|
CWE-77
Command Injection
|
CVE-2024-7679
|
2024-10-2 02:16 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
613
|
- |
|
-
|
-
|
Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is fixed in 2.3.2.
New
|
CWE-78
OS Command
|
CVE-2024-47608
|
2024-10-2 02:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
614
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: Fix uaf in __timer_delete_sync
There are two paths to access mptcp_pm_del_add_timer, result in a race
condition:
…
Update
|
CWE-416
Use After Free
|
CVE-2024-46858
|
2024-10-2 02:10 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
615
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix bridge mode operations when there are no VFs
Currently, trying to set the bridge mode attribute when numvfs=0 leads…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46857
|
2024-10-2 02:10 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
616
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire()
If the __qcuefi pointer is not set, then in the original code, we wo…
Update
|
CWE-667
Improper Locking
|
CVE-2024-46868
|
2024-10-2 02:09 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
617
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/client: fix deadlock in show_meminfo()
There is a real deadlock as well as sleeping in atomic() bug in here, if
the bo put…
Update
|
CWE-667
Improper Locking
|
CVE-2024-46867
|
2024-10-2 02:09 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
618
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/client: add missing bo locking in show_meminfo()
bo_meminfo() wants to inspect bo state like tt and the ttm resource,
howe…
Update
|
CWE-667
Improper Locking
|
CVE-2024-46866
|
2024-10-2 02:09 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
619
|
2.7 |
LOW
Network
|
formtools
|
form_tools
|
A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.php of the component I…
Update
|
NVD-CWE-Other
|
CVE-2024-6937
|
2024-10-2 01:51 |
2024-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
620
|
6.5 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing inte…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2024-6512
|
2024-10-2 01:36 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|