Latest CVE Feed
-
3.3
LOWCVE-2024-50092
In the Linux kernel, the following vulnerability has been resolved: net: netconsole: fix wrong warning A warning is triggered when there is insufficient space in the buffer for userdata. However, this is not an issue since userdata will be sent in the n... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50091
In the Linux kernel, the following vulnerability has been resolved: dm vdo: don't refer to dedupe_context after releasing it Clear the dedupe_context pointer in a data_vio whenever ownership of the context is lost, so that vdo can't examine it accidenta... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 12, 2024
-
5.5
MEDIUMCVE-2024-50090
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix overflow in oa batch buffer By default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch buffer, this is not a problem if batch buffer is only used once but oa re... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Feb. 18, 2025
-
7.8
HIGHCVE-2024-49522
Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim ... Read more
Affected Products : substance_3d_painter- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
5.4
MEDIUMCVE-2024-48312
WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2023-29126
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.0
CRITICALCVE-2023-29125
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.7
MEDIUMCVE-2023-29122
Under certain conditions, access to service libraries is granted to account they should not have access to.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.6
CRITICALCVE-2023-29121
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29120
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29119
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29118
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2023-29117
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2023-29116
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
5.7
MEDIUMCVE-2024-52030
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 02, 2025
-
5.7
MEDIUMCVE-2024-52029
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 02, 2025
-
5.7
MEDIUMCVE-2024-52028
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: May. 02, 2025
-
5.7
MEDIUMCVE-2024-52026
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST reque... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-52025
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST requ... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-52024
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST reques... Read more
- Published: Nov. 05, 2024
- Modified: May. 21, 2025