|
252021
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: fix oops on non-dbdc mt7986
mt7915_band_config() sets band_idx = 1 on the main phy for mt7986
with MT7975_ONE…
|
NVD-CWE-noinfo
|
CVE-2024-47715
|
2024-10-24 23:35 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252022
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ARM: 9410/1: vfp: Use asm volatile in fmrx/fmxr macros
Floating point instructions in userspace can crash some arm kernels
built …
|
NVD-CWE-noinfo
|
CVE-2024-47716
|
2024-10-24 23:34 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252023
|
9.8 |
CRITICAL
Network
|
smartdevth
|
advanced_advertising_system
|
Deserialization of Untrusted Data vulnerability in Smartdevth Advanced Advertising System allows Object Injection.This issue affects Advanced Advertising System: from n/a through 1.3.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-49624
|
2024-10-24 23:34 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252024
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: use hweight16 to get correct tx antenna
The chainmask is u16 so using hweight8 cannot get correct tx_ant.
Wit…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47714
|
2024-10-24 23:33 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252025
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
RISC-V: KVM: Don't zero-out PMU snapshot area before freeing data
With the latest Linux-6.11-rc3, the below NULL pointer crash is…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-47717
|
2024-10-24 23:32 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252026
|
9.8 |
CRITICAL
Network
|
tecno-mobile
|
4g_portable_wifi_tr118_firmware
|
A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/goform_get_cm…
|
CWE-89
SQL Injection
|
CVE-2024-10195
|
2024-10-24 23:28 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252027
|
8.8 |
HIGH
Network
|
apa
|
apa_banner_slider
|
Cross-Site Request Forgery (CSRF) vulnerability in Apa Apa Banner Slider allows SQL Injection.This issue affects Apa Banner Slider: from n/a through 1.0.0.
|
CWE-352
Origin Validation Error
|
CVE-2024-49622
|
2024-10-24 23:25 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252028
|
6.5 |
MEDIUM
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to wait dio completion
It should wait all existing dio write IOs before block removal,
otherwise, previous direct write…
|
NVD-CWE-noinfo
|
CVE-2024-47726
|
2024-10-24 23:24 |
2024-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252029
|
8.8 |
HIGH
Network
|
hasanmovahed
|
duplicate_title_validate
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hasan Movahed Duplicate Title Validate allows Blind SQL Injection.This issue affects Duplicate Ti…
|
CWE-89
SQL Injection
|
CVE-2024-49623
|
2024-10-24 23:18 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252030
|
5.4 |
MEDIUM
Network
|
mdabdulkader
|
easy_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Md Abdul Kader Easy Addons for Elementor allows Stored XSS.This issue affects Easy Addons …
|
CWE-79
Cross-site Scripting
|
CVE-2024-49631
|
2024-10-24 23:12 |
2024-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|