NA - CVE-2024-43802 - Vim is an improved version of the unix vi text...
Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current position in the typeahead buffer but does not check whether there is enough space...
NA - CVE-2024-43806 - Rustix is a set of safe Rust bindings to...
Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is...
NA - CVE-2024-28077 - A denial-of-service issue was discovered on...
A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and...
NA - CVE-2024-42906 - TestLink before v.1.9.20 is vulnerable to Cross...
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
NA - CVE-2024-44793 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted...
NA - CVE-2024-44794 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted...
NA - CVE-2024-44795 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected...
NA - CVE-2024-44796 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload...
NA - CVE-2024-44797 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload...
NA - CVE-2024-8105 - A vulnerability related to the use an insecure...
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a...