4271
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion…
|
-
|
CVE-2024-13502
|
2025-01-17 23:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4272
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker
After commit
746ae46c1113 ("drm/sched: Mar…
|
-
|
CVE-2024-57888
|
2025-01-17 23:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4273
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
mm: hugetlb: independent PMD page table shared count
The folio refcount may be increased unexpectly through try_get_folio() by
ca…
|
-
|
CVE-2024-57883
|
2025-01-17 23:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4274
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ceph: give up on paths longer than PATH_MAX
If the full path to be built by ceph_mdsc_build_path() happens to be
longer than PATH…
|
-
|
CVE-2024-53685
|
2025-01-17 23:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4275
|
- |
|
-
|
-
|
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity
and potential remote code execution on workstation when a non-admin authenticated…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-12703
|
2025-01-17 20:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4276
|
- |
|
-
|
-
|
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could
cause information disclosure of restricted web page, modification of web page and denial of
service…
|
CWE-200
Information Exposure
|
CVE-2024-12142
|
2025-01-17 20:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4277
|
- |
|
-
|
-
|
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that
could allow an unauthorized attacker to modify configuration values outside of the normal ra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-10498
|
2025-01-17 20:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4278
|
- |
|
-
|
-
|
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an
authorized attacker to modify values outside those defined by their privileges (Elevation of Privile…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-10497
|
2025-01-17 20:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4279
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13378
|
2025-01-17 19:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4280
|
7.2 |
HIGH
Network
-
|
-
|
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13377
|
2025-01-17 19:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|