531
|
- |
|
-
|
-
|
In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional e…
|
-
|
CVE-2023-35686
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
532
|
- |
|
-
|
-
|
In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no a…
|
-
|
CVE-2023-35659
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
533
|
- |
|
-
|
-
|
A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafa…
|
-
|
CVE-2024-9476
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
534
|
- |
|
-
|
-
|
The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, potentially allowing an Application Processor (AP) to cause a buffer overflow in…
|
-
|
CVE-2024-9413
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
535
|
- |
|
-
|
-
|
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, r…
|
CWE-22 CWE-552
Path Traversal Files or Directories Accessible to External Parties
|
CVE-2024-52292
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
536
|
- |
|
-
|
-
|
Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This e…
|
CWE-22
Path Traversal
|
CVE-2024-52291
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
537
|
- |
|
-
|
-
|
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted i…
|
CWE-287 CWE-289
Improper Authentication Authentication Bypass by Alternate Name
|
CVE-2024-51996
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
538
|
- |
|
-
|
-
|
Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a malformed URL. This vulnerability is fixe…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45594
|
2024-11-15 23:00 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
539
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPrevi…
|
CWE-22
Path Traversal
|
CVE-2024-11238
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
540
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Pars…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2024-11237
|
2024-11-15 22:58 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|