-
CVE-2024-34748 – DevmemX Use-After-Free Local Kernel EoP
CVE ID : CVE-2024-34748 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Severity:…
-
CVE-2025-22217 – VMware Avi Load Balancer Blind SQL Injection
CVE ID : CVE-2025-22217 Published : Jan. 28, 2025, 7:15 p.m. | 12 hours, 44 minutes ago Description : Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use…
-
CVE-2024-34732 – Vulnerability in RGX MMUCache Invalidate in AMD Device
CVE ID : CVE-2024-34732 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed…
-
CVE-2024-13484 – ArgoCD Cluster-Wide PrometheusRule Injection Vulnerability
CVE ID : CVE-2024-13484 Published : Jan. 28, 2025, 6:15 p.m. | 13 hours, 44 minutes ago Description : A flaw was found in ArgoCD. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring…
-
CVE-2018-9373 – MTK WLAN Driver Out-of-Bounds Write Privilege Escalation Vulnerability
CVE ID : CVE-2018-9373 Published : Jan. 28, 2025, 5:15 p.m. | 14 hours, 45 minutes ago Description : In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is…
-
CVE-2025-0781 – FSFlight Tracker Nasal Privilege Escalation RCE
CVE ID : CVE-2025-0781 Published : Jan. 28, 2025, 5:15 p.m. | 14 hours, 44 minutes ago Description : An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level. Severity: 8.6 | HIGH Visit the link for more details, such…
-
CVE-2025-23213 – Tandoor Recipes Cross-Site Scripting (XSS)
CVE ID : CVE-2025-23213 Published : Jan. 28, 2025, 4:15 p.m. | 15 hours, 44 minutes ago Description : Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed…