|
250081
|
8.8 |
HIGH
Network
|
liferay
|
digital_experience_platform liferay_portal
|
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 up…
|
CWE-352
Origin Validation Error
|
CVE-2024-26271
|
2024-10-31 00:04 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250082
|
8.8 |
HIGH
Network
|
liferay
|
digital_experience_platform liferay_portal
|
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA …
|
CWE-352
Origin Validation Error
|
CVE-2024-26273
|
2024-10-31 00:03 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250083
|
8.8 |
HIGH
Network
|
liferay
|
digital_experience_platform liferay_portal
|
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA …
|
CWE-352
Origin Validation Error
|
CVE-2024-26272
|
2024-10-31 00:03 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250084
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()
Commit a3c1e45156ad ("net: microchip: vcap: Fix use-aft…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50084
|
2024-10-30 23:56 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250085
|
9.8 |
CRITICAL
Network
|
snyk
|
snyk_cli
|
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to…
|
CWE-78
OS Command
|
CVE-2024-48963
|
2024-10-30 23:54 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250086
|
9.8 |
CRITICAL
Network
|
razormist
|
payroll_management_system
|
A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-10371
|
2024-10-30 23:51 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250087
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
Syzkaller reported this splat:
=====================================…
|
CWE-416
Use After Free
|
CVE-2024-50085
|
2024-10-30 23:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250088
|
8.8 |
HIGH
Network
|
liferay
|
digital_experience_platform liferay_portal
|
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does …
|
CWE-863
Incorrect Authorization
|
CVE-2024-38002
|
2024-10-30 23:47 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250089
|
6.1 |
MEDIUM
Network
|
liferay
|
digital_experience_platform liferay_portal
|
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA throu…
|
CWE-352
Origin Validation Error
|
CVE-2024-8980
|
2024-10-30 23:46 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250090
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix uninitialized pointer free on read_alloc_one_name() error
The function read_alloc_one_name() does not initialize the n…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2024-50087
|
2024-10-30 23:40 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|