| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-35783 | Cri | 0.59 | 9.1 | 0.01 | Sep 10, 2024 | A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process… | ||
| CVE-2024-33698 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All… | ||
| CVE-2024-6596 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | ||
| CVE-2024-6342 | Cri | 0.64 | 9.8 | 0.02 | Sep 10, 2024 | **UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system… | ||
| CVE-2024-44411 | Cri | 0.64 | 9.8 | 0.04 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. | ||
| CVE-2024-44410 | Cri | 0.64 | 9.8 | 0.03 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. | ||
| CVE-2024-6795 | Cri | 0.65 | 10.0 | 0.01 | Sep 9, 2024 | In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that… | ||
| CVE-2024-44902 | Cri | 0.64 | 9.8 | 0.04 | Sep 9, 2024 | A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | ||
| CVE-2024-42500 | Cri | 0.60 | 9.3 | 0.00 | Sep 9, 2024 | HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services. | ||
| CVE-2024-44849 | Cri | 0.67 | 9.8 | 0.46 | Sep 9, 2024 | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. | ||
| CVE-2024-44721 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2024 | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php. | ||
| CVE-2024-40643 | Cri | 0.55 | 9.6 | 0.01 | Sep 9, 2024 | Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag. | ||
| CVE-2024-7015 | Cri | 0.64 | 9.8 | 0.00 | Sep 9, 2024 | Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2. | ||
| CVE-2024-37288 | Cri | 0.64 | 9.9 | 0.01 | Sep 9, 2024 | A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-fo… | ||
| CVE-2024-8584 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2024 | Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. | ||
| CVE-2024-6928 | Cri | 0.64 | 9.8 | 0.03 | Sep 8, 2024 | The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | ||
| CVE-2024-6924 | Cri | 0.64 | 9.8 | 0.03 | Sep 8, 2024 | The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | ||
| CVE-2024-40711 | Cri | 0.89 | 9.8 | 0.90 | KEV | Sep 7, 2024 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | |
| CVE-2024-39714 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2024 | A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server. | ||
| CVE-2024-38650 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2024 | An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server. | ||
| CVE-2024-45771 | Cri | 0.64 | 9.8 | 0.00 | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php. | ||
| CVE-2024-44839 | Cri | 0.64 | 9.8 | 0.00 | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php. | ||
| CVE-2024-44838 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php. | ||
| CVE-2024-8517 | Cri | 0.74 | 9.8 | 0.95 | Sep 6, 2024 | SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request. | ||
| CVE-2024-45758 | — | Cri | 0.52 | 9.1 | 0.01 | Sep 6, 2024 | H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON document containing a… | |
| CVE-2024-44402 | Cri | 0.64 | 9.8 | 0.03 | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. | ||
| CVE-2024-44401 | Cri | 0.64 | 9.8 | 0.03 | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file | ||
| CVE-2024-7493 | Cri | 0.57 | 9.8 | 0.01 | Sep 6, 2024 | The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers… | ||
| CVE-2024-8292 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2024 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This… | ||
| CVE-2024-8395 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2024 | FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication. | ||
| CVE-2024-45159 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of… | ||
| CVE-2024-45158 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2024 | An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits… | ||
| CVE-2024-7591 | Cri | 0.69 | 10.0 | 0.44 | Sep 5, 2024 | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above | ||
| CVE-2024-44727 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2024 | Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php. | ||
| CVE-2024-24759 | Cri | 0.54 | 9.3 | 0.05 | Sep 5, 2024 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service.… | ||
| CVE-2024-42885 | Cri | 0.59 | 9.1 | 0.01 | Sep 5, 2024 | SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page. | ||
| CVE-2024-8470 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8469 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it. | ||
| CVE-2024-8468 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it. | ||
| CVE-2024-8467 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it. | ||
| CVE-2024-8466 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8465 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8464 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8463 | Cri | 0.64 | 9.9 | 0.01 | Sep 5, 2024 | File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell. | ||
| CVE-2024-43102 | Cri | 0.65 | 10.0 | 0.01 | Sep 5, 2024 | Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early. A malicious code… | ||
| CVE-2024-44998 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() because the skb is released. | ||
| CVE-2024-44985 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UAF in ip6_xmit() If skb_expand_head() returns NULL, skb has been freed and the associated dst/idev could also have been freed. We must use rcu_read_lock() to prevent a possible UAF. | ||
| CVE-2024-44984 | Cri | 0.65 | 10.0 | 0.01 | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT Remove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT code path. This should have been removed when we let the page pool handle the DMA… | ||
| CVE-2024-44970 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible to receive CQEs… | ||
| CVE-2024-20439 | Cri | 0.83 | 9.8 | 0.97 | KEV | Sep 4, 2024 | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative… |
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All…
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
- risk 0.64cvss 9.8epss 0.02
**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system…
- risk 0.64cvss 9.8epss 0.04
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
- risk 0.65cvss 10.0epss 0.01
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that…
- risk 0.64cvss 9.8epss 0.04
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
- risk 0.60cvss 9.3epss 0.00
HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.
- risk 0.67cvss 9.8epss 0.46
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
- risk 0.55cvss 9.6epss 0.01
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
- risk 0.64cvss 9.8epss 0.00
Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2.
- risk 0.64cvss 9.9epss 0.01
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-fo…
- risk 0.64cvss 9.8epss 0.01
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
- risk 0.64cvss 9.8epss 0.03
The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- risk 0.64cvss 9.8epss 0.03
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- risk 0.89cvss 9.8epss 0.90
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- risk 0.64cvss 9.9epss 0.01
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
- risk 0.64cvss 9.9epss 0.01
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
- risk 0.64cvss 9.8epss 0.00
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.
- risk 0.64cvss 9.8epss 0.00
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.
- risk 0.64cvss 9.8epss 0.01
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.
- risk 0.74cvss 9.8epss 0.95
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
- risk 0.52cvss 9.1epss 0.01
H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON document containing a…
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
- risk 0.57cvss 9.8epss 0.01
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers…
- risk 0.64cvss 9.8epss 0.01
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This…
- risk 0.64cvss 9.8epss 0.01
FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.
- risk 0.64cvss 9.8epss 0.00
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits…
- risk 0.69cvss 10.0epss 0.44
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
- risk 0.64cvss 9.8epss 0.01
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
- risk 0.54cvss 9.3epss 0.05
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service.…
- risk 0.59cvss 9.1epss 0.01
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.9epss 0.01
File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.
- risk 0.65cvss 10.0epss 0.01
Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early. A malicious code…
- risk 0.64cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() because the skb is released.
- risk 0.64cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UAF in ip6_xmit() If skb_expand_head() returns NULL, skb has been freed and the associated dst/idev could also have been freed. We must use rcu_read_lock() to prevent a possible UAF.
- risk 0.65cvss 10.0epss 0.01
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT Remove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT code path. This should have been removed when we let the page pool handle the DMA…
- risk 0.64cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possible to receive CQEs…
- risk 0.83cvss 9.8epss 0.97
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative…