1931
|
4.6 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…
|
CWE-79
Cross-site Scripting
|
CVE-2023-32340
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1932
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or al…
|
-
|
CVE-2024-42183
|
2025-01-23 11:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1933
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server on localhost.
|
-
|
CVE-2024-42182
|
2025-01-23 10:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1934
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: avoid NULL pointer dereference if no valid extent tree
[BUG]
Syzbot reported a crash with the following call trace:
BTR…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-21658
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1935
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ti-ads1298: Add NULL check in ads1298_init
devm_kasprintf() can return a NULL pointer on failure. A check on the
return…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-57944
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1936
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sctp: Prevent autoclose integer overflow in sctp_association_init()
While by default max_autoclose equals to INT_MAX / HZ, on…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-57938
|
2025-01-23 08:01 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1937
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12477
|
2025-01-23 07:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1938
|
- |
|
-
|
-
|
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.
|
-
|
CVE-2024-57545
|
2025-01-23 07:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1939
|
- |
|
-
|
-
|
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.
|
-
|
CVE-2024-57544
|
2025-01-23 07:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1940
|
- |
|
-
|
-
|
Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.
|
-
|
CVE-2024-55958
|
2025-01-23 07:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|