NVD disclosure day

Published threat advisories for March 25, 2024

CVE advisoryCRITICAL

CVE-2024-2865

Mergen Quality Management System SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Mergen Software Quality Management System allows for unauthorized data access and modification through SQL injection. This impacts data integrity and could lead to unauthorized control of the system, posing a business risk. Organizations using this system should assess their exposure and implemen

CVE advisoryCRITICAL

CVE-2024-28386

Home-Made fastmagsync Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated remote code execution vulnerability exists in the fastmagsync component of Home-Made.io, potentially allowing attackers to run unauthorized code via the `getPhpBin()` function. This could lead to system compromise if the component is reachable over the network. Readers should verify if this technolog

CVE advisoryCRITICAL

CVE-2021-47137

Linux Kernel Lantiq Memory Corruption in RX Ring

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Linux kernel's Lantiq network driver can cause memory corruption due to memory allocation failures, potentially impacting system stability. This vulnerability requires network access to exploit and could lead to data integrity issues if not addressed. Identifying affected systems and assessing their netwo