Total
271657 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-38382 | 1 Openatom | 1 Openharmony | 2024-09-04 | N/A | 5.5 MEDIUM |
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | |||||
CVE-2024-33042 | 1 Qualcomm | 406 205, 205 Firmware, 215 and 403 more | 2024-09-04 | N/A | 7.8 HIGH |
Memory corruption when Alternative Frequency offset value is set to 255. | |||||
CVE-2024-33047 | 1 Qualcomm | 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more | 2024-09-04 | N/A | 7.8 HIGH |
Memory corruption when the captureRead QDCM command is invoked from user-space. | |||||
CVE-2024-33050 | 1 Qualcomm | 514 Ar8035, Ar8035 Firmware, Ar9380 and 511 more | 2024-09-04 | N/A | 7.5 HIGH |
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | |||||
CVE-2024-33054 | 1 Qualcomm | 66 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 63 more | 2024-09-04 | N/A | 7.8 HIGH |
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. | |||||
CVE-2024-33057 | 1 Qualcomm | 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more | 2024-09-04 | N/A | 7.5 HIGH |
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. | |||||
CVE-2024-33060 | 1 Qualcomm | 500 215 Mobile, 215 Mobile Firmware, 315 5g Iot and 497 more | 2024-09-04 | N/A | 7.8 HIGH |
Memory corruption when two threads try to map and unmap a single node simultaneously. | |||||
CVE-2024-38401 | 1 Qualcomm | 80 Ar8035, Ar8035 Firmware, C-v2x 9150 and 77 more | 2024-09-04 | N/A | 7.8 HIGH |
Memory corruption while processing concurrent IOCTL calls. | |||||
CVE-2024-41162 | 1 Mattermost | 1 Mattermost Server | 2024-09-04 | N/A | 4.3 MEDIUM |
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only. | |||||
CVE-2024-38386 | 1 Openatom | 1 Openharmony | 2024-09-04 | N/A | 7.8 HIGH |
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | |||||
CVE-2024-41926 | 1 Mattermost | 1 Mattermost Server | 2024-09-04 | N/A | 4.3 MEDIUM |
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote. | |||||
CVE-2024-45509 | 1 Misp | 1 Misp | 2024-09-04 | N/A | 6.5 MEDIUM |
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin. | |||||
CVE-2024-45508 | 1 Htmldoc Project | 1 Htmldoc | 2024-09-04 | N/A | 9.8 CRITICAL |
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. | |||||
CVE-2024-8348 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2024-09-04 | 6.5 MEDIUM | 9.8 CRITICAL |
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-8347 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2024-09-04 | 6.5 MEDIUM | 9.8 CRITICAL |
A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-44684 | 1 Tpmecms | 1 Tpmecms | 2024-09-04 | N/A | 6.1 MEDIUM |
TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields. | |||||
CVE-2024-44683 | 1 Seacms | 1 Seacms | 2024-09-04 | N/A | 6.1 MEDIUM |
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. | |||||
CVE-2024-39612 | 1 Openatom | 1 Openharmony | 2024-09-04 | N/A | 5.5 MEDIUM |
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | |||||
CVE-2024-44682 | 1 Shopxo | 1 Shopxo | 2024-09-04 | N/A | 6.1 MEDIUM |
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters. | |||||
CVE-2024-8346 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2024-09-04 | 6.5 MEDIUM | 9.8 CRITICAL |
A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |