651
|
- |
|
-
|
-
|
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
|
-
|
CVE-2024-54761
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
652
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ar8035_firmware c-v2x_9150_firmware csrb31024_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware msm8996au_firmware qam8295p_firmware qca63…
|
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33067
|
2025-01-11 00:39 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
653
|
5.5 |
MEDIUM
Local
|
qualcomm
|
qam8255p_firmware qam8295p_firmware qam8650p_firmware qam8775p_firmware qamsrv1h_firmware qca6595_firmware qca6595au_firmware qca6696_firmware qca6698aq_firmware sa8255p_fi…
|
information disclosure while invoking the mailbox read API.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-43063
|
2025-01-11 00:37 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
654
|
7.8 |
HIGH
Local
|
google
|
android
|
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional e…
|
NVD-CWE-noinfo
|
CVE-2023-35685
|
2025-01-11 00:30 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
655
|
- |
|
-
|
-
|
A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "page…
|
-
|
CVE-2024-57686
|
2025-01-11 00:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
656
|
- |
|
-
|
-
|
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
|
-
|
CVE-2024-57822
|
2025-01-11 00:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
657
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.
|
-
|
CVE-2024-13288
|
2025-01-11 00:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
658
|
9.8 |
CRITICAL
Network
-
|
-
|
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, a…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2024-41787
|
2025-01-10 23:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
659
|
- |
|
-
|
-
|
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().
|
-
|
CVE-2024-57823
|
2025-01-10 23:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
660
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. This affects an unknown part of the file /web_caps/webC…
|
-
|
CVE-2024-13131
|
2025-01-10 23:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|