Aggregator
CVE-2024-30983 | PHPGurukul Cyber Cafe Management System 1.0 edit-computer-detail.php compname sql injection
10 months 1 week ago
A vulnerability was found in PHPGurukul Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /edit-computer-detail.php. The manipulation of the argument compname leads to sql injection.
This vulnerability is traded as CVE-2024-30983. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-30982 | PHPGurukul Cyber Cafe Management System 1.0 /view-user-detail.php upid sql injection
10 months 1 week ago
A vulnerability classified as critical has been found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /view-user-detail.php. The manipulation of the argument upid leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-30982. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-35845 | Linux Kernel up to 6.8.1 iwlwifi iwl_fw_ini_debug_info_tlv null termination
10 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.8.1. It has been classified as problematic. Affected is the function iwl_fw_ini_debug_info_tlv of the component iwlwifi. The manipulation leads to improper null termination.
This vulnerability is traded as CVE-2024-35845. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30981 | PHPGurukul Cyber Cafe Management System 1.0 edit-computer-detail.php editid sql injection
10 months 1 week ago
A vulnerability classified as critical was found in PHPGurukul Cyber Cafe Management System 1.0. This vulnerability affects unknown code of the file /edit-computer-detail.php. The manipulation of the argument editid leads to sql injection.
This vulnerability was named CVE-2024-30981. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-35869 | Linux Kernel up to 6.6.28/6.8.4 SMB Client use after free (645f332c6b63/e1db9ae87b71/062a7f0ff46e / Nessus ID 210815)
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.28/6.8.4. Affected is an unknown function of the component SMB Client. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-35869. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35865 | Linux Kernel up to 6.1.84/6.6.25/6.8.4 SMB Client smb2_is_valid_oplock_break use after free (Nessus ID 210815)
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.1.84/6.6.25/6.8.4. This affects the function smb2_is_valid_oplock_break of the component SMB Client. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-35865. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35843 | Linux Kernel up to 6.8.1 iommu pci_get_domain_bus_and_slot use after free (3d39238991e7/def054b01a86 / Nessus ID 210815)
10 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.8.1 and classified as problematic. This issue affects the function pci_get_domain_bus_and_slot of the component iommu. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-35843. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35854 | Linux Kernel up to 6.8.8 spectrum_acl_tcam use after free (Nessus ID 209785)
10 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.8.8. It has been rated as problematic. This issue affects some unknown processing of the component spectrum_acl_tcam. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-35854. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35853 | Linux Kernel up to 6.8.8 spectrum_acl_tcam lib/parman.c memory leak (Nessus ID 209785)
10 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.8.8 and classified as critical. Affected by this issue is some unknown functionality in the library lib/parman.c of the component spectrum_acl_tcam. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2024-35853. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CTEM + CREM: Aligning Your Cybersecurity Strategy
10 months 1 week ago
Cyber threats evolve daily, and organizations need to move beyond traditional security approaches to stay ahead. That’s why Continuous Threat Exposure Management (CTEM), a concept introduced by Gartner, has been gaining traction. CTEM isn’t just another cybersecurity buzzword; it’s a structured, continuous program designed to help organizations identify, assess, and mitigate security risks proactively. If you’re considering implementing a CTEM program, Trend Vision One TM Cyber Risk Exposure Management (CREM) solution—formerly known as Attack Surface Risk Management (ASRM)—can give you a significant head start.
Alifiya Sadikali
[webapps] WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation
10 months 1 week ago
WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation
[webapps] Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
10 months 1 week ago
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
[webapps] UNA CMS 14.0.0-RC - PHP Object Injection
10 months 1 week ago
UNA CMS 14.0.0-RC - PHP Object Injection
[webapps] Jasmin Ransomware - Arbitrary File Download (Authenticated)
10 months 1 week ago
Jasmin Ransomware - Arbitrary File Download (Authenticated)
[webapps] jQuery 3.3.1 - Prototype Pollution & XSS Exploit
10 months 1 week ago
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
[remote] InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
10 months 1 week ago
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
[remote] Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
10 months 1 week ago
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
[webapps] GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
10 months 1 week ago
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
威努特鲲鹏服务器安全一体机:领航ARM架构与安全体系革新
10 months 1 week ago
为企业构建一个安全、高效、绿色的计算环境。