-
CVE-2025-0803 – Codezips Gym Management System SQL Injection Vulnerability
CVE ID : CVE-2025-0803 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_new.php. The manipulation of the argument planid leads to sql injection.…
-
CVE-2025-0800 – SourceCodester Online Courseware Cross Site Scripting
CVE ID : CVE-2025-0800 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting.…
-
CVE-2025-0798 – MicroWorld eScan Antivirus os Command Injection Vulnerability
CVE ID : CVE-2025-0798 Published : Jan. 29, 2025, 2:15 a.m. | 5 hours, 44 minutes ago Description : A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command…
-
CVE-2024-40672 – Samsung Android ChooserActivity Java Missing Permission Check Privilege Escalation Vulnerability
CVE ID : CVE-2024-40672 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
-
CVE-2024-40677 – Samsung AdvancedPowerUsage Denial of Service Local Privilege Escalation
CVE ID : CVE-2024-40677 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
-
CVE-2024-40669 – Apache TBD Heap Use-After-Free Local Privilege Escalation Vulnerability
CVE ID : CVE-2024-40669 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Severity:…
-
CVE-2024-40670 – Adobe Reader Use After Free (Local Privilege Escalation)
CVE ID : CVE-2024-40670 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Severity:…
-
CVE-2024-40649 – Apache Linux Kernel Use-After-Free Local Privilege Escalation
CVE ID : CVE-2024-40649 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not…
-
CVE-2024-40651 – ┌ Linux Kernel Use-After-Free Vulnerability in TBD
CVE ID : CVE-2024-40651 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not…
-
CVE-2024-34733 – Apache DRAM Arbitrary Code Execution Vulnerability
CVE ID : CVE-2024-34733 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed…