91
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File En…
New
|
-
|
CVE-2024-13237
|
2025-01-10 06:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
92
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration()
acpi_dev_hid_match() does not check for adev == NULL, dere…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-56782
|
2025-01-10 06:00 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
93
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: add a sanity check for btrfs root in btrfs_search_slot()
Syzbot reports a null-ptr-deref in btrfs_search_slot().
The repr…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-56774
|
2025-01-10 06:00 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
94
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
kunit: Fix potential null dereference in kunit_device_driver_test()
kunit_kzalloc() may return a NULL pointer, dereferencing it w…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-56773
|
2025-01-10 05:59 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
95
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
kunit: string-stream: Fix a UAF bug in kunit_init_suite()
In kunit_debugfs_create_suite(), if alloc_string_stream() fails in the
…
New
|
CWE-416
Use After Free
|
CVE-2024-56772
|
2025-01-10 05:57 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
96
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE
I expect that the hardware will have limited this to 16, but just in
case it ha…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2022-49035
|
2025-01-10 05:22 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
97
|
- |
|
-
|
-
|
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designate…
New
|
-
|
CVE-2024-56114
|
2025-01-10 05:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
98
|
- |
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter a…
New
|
-
|
CVE-2024-55494
|
2025-01-10 05:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
99
|
- |
|
-
|
-
|
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an a…
New
|
-
|
CVE-2024-54887
|
2025-01-10 05:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
100
|
- |
|
-
|
-
|
PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.
New
|
-
|
CVE-2024-54724
|
2025-01-10 05:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|