|
303361
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix command bitmask initialization
Command bitmask have a dedicated bit for MANAGE_PAGES command, this bit
isn't Initia…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50147
|
2024-11-19 06:19 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303362
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: fix unbalanced rpm put() with fence_fini()
Currently we can call fence_fini() twice if something goes wrong when
sending …
|
NVD-CWE-noinfo
|
CVE-2024-50144
|
2024-11-19 06:16 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303363
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2016
|
Active Directory Certificate Services Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-49019
|
2024-11-19 06:12 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303364
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2025 windows_10_1809 windows_server_2019 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_serv…
|
Windows Telephony Service Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43627
|
2024-11-19 05:58 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303365
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2025 windows_10_1809 windows_server_2019 windows_server_2022 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_…
|
Windows Telephony Service Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-43628
|
2024-11-19 05:46 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303366
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or …
|
-
|
CVE-2024-42834
|
2024-11-19 05:35 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303367
|
- |
|
-
|
-
|
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
|
-
|
CVE-2024-40443
|
2024-11-19 05:35 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303368
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.
|
-
|
CVE-2023-38920
|
2024-11-19 05:35 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303369
|
7.2 |
HIGH
Network
|
angeljudesuarez
|
construction_management_system
|
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
|
CWE-89
SQL Injection
|
CVE-2024-50972
|
2024-11-19 05:35 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303370
|
7.2 |
HIGH
Network
|
angeljudesuarez
|
construction_management_system
|
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
|
CWE-89
SQL Injection
|
CVE-2024-50971
|
2024-11-19 05:35 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|