Latest CVE Feed
-
6.9
MEDIUMCVE-2024-8604
A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name l... Read more
- Published: Sep. 09, 2024
- Modified: Sep. 10, 2024
-
4.7
MEDIUMCVE-2024-42287
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Complete command early within lock A crash was observed while performing NPIV and FW reset, BUG: kernel NULL pointer dereference, address: 000000000000001c #PF: superv... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-42286
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: validate nvme_local_port correctly The driver load failed with error message, qla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef and with a kernel c... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 10, 2024
-
9.8
CRITICALCVE-2024-44410
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.... Read more
- Published: Sep. 09, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-42344
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an a... Read more
- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
5.3
MEDIUMCVE-2024-42345
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional m... Read more
Affected Products : sinema_remote_connect_server- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-42277
In the Linux kernel, the following vulnerability has been resolved: iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en In sprd_iommu_cleanup() before calling function sprd_iommu_hw_en() dom->sdev is equal to NULL, which leads to null dereference. Found ... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 10, 2024
-
7.8
HIGHCVE-2024-42280
In the Linux kernel, the following vulnerability has been resolved: mISDN: Fix a use after free in hfcmulti_tx() Don't dereference *sp after calling dev_kfree_skb(*sp).... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-42298
In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but this returned value is not checked. Fix this lack and check th... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-43893
In the Linux kernel, the following vulnerability has been resolved: serial: core: check uartclk for zero to avoid divide by zero Calling ioctl TIOCSSERIAL with an invalid baud_base can result in uartclk being zero, which will result in a divide by zero ... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2024-43894
In the Linux kernel, the following vulnerability has been resolved: drm/client: fix null pointer dereference in drm_client_modeset_probe In drm_client_modeset_probe(), the return value of drm_mode_duplicate() is assigned to modeset->mode, which will lea... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Sep. 10, 2024
-
5.5
MEDIUMCVE-2023-52915
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former chec... Read more
Affected Products : linux_kernel- Published: Sep. 06, 2024
- Modified: Sep. 10, 2024
-
7.5
HIGHCVE-2024-44408
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 10, 2024
-
9.8
CRITICALCVE-2024-44402
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 10, 2024
-
7.1
HIGHCVE-2024-44983
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate vlan header Ensure there is sufficient room to access the protocol field of the VLAN header, validate it once before the flowtable lookup. ==============... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 10, 2024
-
7.8
HIGHCVE-2024-44978
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Free job before xe_exec_queue_put Free job depends on job->vm being valid, the last xe_exec_queue_put can destroy the VM. Prevent UAF by freeing job before xe_exec_queue_put. (... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 10, 2024
-
9.3
CRITICALCVE-2024-42348
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.... Read more
Affected Products : fogproject- Published: Aug. 02, 2024
- Modified: Sep. 10, 2024
-
5.3
MEDIUMCVE-2024-42349
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. FOG Server creates 2 logs on the root of the web server (... Read more
- Published: Aug. 02, 2024
- Modified: Sep. 10, 2024
-
9.8
CRITICALCVE-2024-38886
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: Sep. 10, 2024
-
9.8
CRITICALCVE-2024-38889
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: Sep. 10, 2024