621
|
- |
|
-
|
-
|
A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.
New
|
-
|
CVE-2024-9110
|
2024-10-31 02:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
622
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.
New
|
-
|
CVE-2024-51258
|
2024-10-31 02:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
623
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.
Update
|
CWE-59
Link Following
|
CVE-2024-44175
|
2024-10-31 02:14 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
624
|
4.9 |
MEDIUM
Network
|
mayurik
|
petrol_pump_management
|
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoic…
Update
|
CWE-89
SQL Injection
|
CVE-2024-10355
|
2024-10-31 02:13 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
625
|
3.3 |
LOW
Local
|
apple
|
iphone_os ipados
|
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to enable Auto-Answer Calls.
Update
|
NVD-CWE-noinfo
|
CVE-2024-40853
|
2024-10-31 02:08 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
626
|
3.3 |
LOW
Local
|
apple
|
macos
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to read sensitive location information.
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-27849
|
2024-10-31 02:07 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
627
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work
When the sqpoll is exiting and cancels pending work ite…
Update
|
NVD-CWE-noinfo
|
CVE-2024-50079
|
2024-10-31 02:05 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
628
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func()
'new_map' is allocated using devm_* which takes care of…
Update
|
CWE-415
Double Free
|
CVE-2024-50071
|
2024-10-31 02:02 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
629
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: stm32: check devm_kasprintf() returned value
devm_kasprintf() can return a NULL pointer on failure but this returned
val…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50070
|
2024-10-31 01:59 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
630
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: apple: check devm_kasprintf() returned value
devm_kasprintf() can return a NULL pointer on failure but this returned
val…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50069
|
2024-10-31 01:58 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|