|
307441
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
cachefiles: fix dentry leak in cachefiles_open_file()
A dentry leak may be caused when a lookup cookie and a cull are concurrent:…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-49870
|
2024-10-25 21:55 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307442
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 0.9.5 due to insufficient input sanitization and output es…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10343
|
2024-10-25 18:15 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307443
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10112
|
2024-10-25 18:15 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307444
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.0 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10016
|
2024-10-25 18:15 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307445
|
8.8 |
HIGH
Network
|
-
|
-
|
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce va…
|
CWE-352
Origin Validation Error
|
CVE-2024-9598
|
2024-10-25 17:15 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307446
|
- |
|
-
|
-
|
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
|
-
|
CVE-2024-50583
|
2024-10-25 16:15 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307447
|
- |
|
-
|
-
|
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserv…
|
-
|
CVE-2023-49233
|
2024-10-25 05:35 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307448
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. (Chromium security severity: Medium)
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7973
|
2024-10-25 05:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307449
|
- |
|
-
|
-
|
Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.
|
-
|
CVE-2023-29929
|
2024-10-25 05:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307450
|
- |
|
-
|
-
|
In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vul…
|
-
|
CVE-2024-42815
|
2024-10-25 05:35 |
2024-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|