721
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()
Commit a3c1e45156ad ("net: microchip: vcap: Fix use-aft…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50084
|
2024-10-30 23:56 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
722
|
9.8 |
CRITICAL
Network
snyk
|
snyk_cli
|
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to…
Update
|
CWE-78
OS Command
|
CVE-2024-48963
|
2024-10-30 23:54 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
723
|
9.8 |
CRITICAL
Network
razormist
|
payroll_management_system
|
A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-10371
|
2024-10-30 23:51 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
724
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
Syzkaller reported this splat:
=====================================…
Update
|
CWE-416
Use After Free
|
CVE-2024-50085
|
2024-10-30 23:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
725
|
8.8 |
HIGH
Network
|
liferay
|
digital_experience_platform liferay_portal
|
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2024-38002
|
2024-10-30 23:47 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
726
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix user-after-free from session log off
There is racy issue between smb2 session log off and smb2 session setup.
It will …
Update
|
CWE-416
Use After Free
|
CVE-2024-50086
|
2024-10-30 23:46 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
727
|
6.1 |
MEDIUM
Network
|
liferay
|
digital_experience_platform liferay_portal
|
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA throu…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-8980
|
2024-10-30 23:46 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
728
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix uninitialized pointer free on read_alloc_one_name() error
The function read_alloc_one_name() does not initialize the n…
Update
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2024-50087
|
2024-10-30 23:40 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
729
|
- |
|
-
|
-
|
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenti…
New
|
-
|
CVE-2024-51568
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
730
|
- |
|
-
|
-
|
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstat…
New
|
-
|
CVE-2024-51567
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|