681
|
- |
|
-
|
-
|
In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no a…
New
|
-
|
CVE-2023-35659
|
2024-11-14 03:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
682
|
7.5 |
HIGH
Network
level1
|
wbr-6012_firmware
|
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot. This could lea…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-31152
|
2024-11-14 03:15 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
683
|
8.1 |
HIGH
Network
|
level1
|
wbr-6012_firmware
|
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can forc…
Update
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-28875
|
2024-11-14 03:10 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
684
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ntfs3: Add bounds checking to mi_enum_attr()
Added bounds checking to make sure that every attr don't stray beyond
valid memory r…
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-50248
|
2024-11-14 03:07 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
685
|
7.5 |
HIGH
Network
level1
|
wbr-6012_firmware
|
The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and small offices while aiming to be easy to configure and operate. In addition to pro…
Update
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2024-28052
|
2024-11-14 03:07 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
686
|
5.4 |
MEDIUM
Network
|
themepunch
|
slider_revolution
|
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and ou…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-8107
|
2024-11-14 03:06 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
687
|
5.4 |
MEDIUM
Network
|
benjaminzekavica
|
easy_svg_support
|
The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.7 due to insufficient input sanitization a…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-10269
|
2024-11-14 02:59 |
2024-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
688
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Check if more than chunk-size bytes are written
A incorrectly formatted chunk may decompress into
more than LZNT_CHUNK_…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-50247
|
2024-11-14 02:58 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
689
|
7.2 |
HIGH
Network
|
wavlink
|
wn530h4_firmware wn530hg4_firmware wn572hg3_firmware
|
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the arg…
Update
|
CWE-77
Command Injection
|
CVE-2024-10429
|
2024-11-14 02:58 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
690
|
7.2 |
HIGH
Network
|
wavlink
|
wn530h4_firmware wn530hg4_firmware wn572hg3_firmware
|
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation …
Update
|
CWE-77
Command Injection
|
CVE-2024-10428
|
2024-11-14 02:57 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|