CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-6604

    Last Modified: 3 Nov 2025

    A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

    Published: 6 Jan 2025
    4.7
    Medium

    CVE-2023-6601

    Last Modified: 3 Nov 2025

    A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.

    Published: 6 Jan 2025
    3.1
    Low

    CVE-2024-51472

    Last Modified: 27 Aug 2025

    IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2025-21618

    Last Modified: 15 Apr 2026

    NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. This vulnerability is fixed in 2.9.1.

    Published: 6 Jan 2025
    5.5
    Medium

    CVE-2025-21615

    Last Modified: 15 Apr 2026

    AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to data exfiltration from malicious apps installed on the same device.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2025-21614

    Last Modified: 30 Sept 2025

    go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.

    Published: 6 Jan 2025
    —
    Unknown

    CVE-2024-13154

    Last Modified: 13 Jan 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: 2024-13362. Reason: This candidate is a reservation duplicate of 2024-13362. Notes: All CVE users should reference 2024-13362 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 Jan 2025
    9.2
    Critical

    CVE-2025-21613

    Last Modified: 17 Apr 2025

    go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.

    Published: 6 Jan 2025
    6.4
    Medium

    CVE-2024-31914

    Last Modified: 29 Sept 2025

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 6 Jan 2025
    5.5
    Medium

    CVE-2024-31913

    Last Modified: 5 Mar 2025

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 6 Jan 2025
    8.6
    High

    CVE-2025-21612

    Last Modified: 15 Apr 2026

    TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.

    Published: 6 Jan 2025
    8.8
    High

    CVE-2025-21611

    Last Modified: 19 Aug 2025

    tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if a user was enabled. This allows enabled users access to most, but not all, authorized actions regardless of their permissions. Notably, the WriteUsers right is unaffected so users may not use this bug to permanently elevate their account permissions. The fix is release in tgstation-server-v6.12.3.

    Published: 6 Jan 2025
    6.9
    Medium

    CVE-2025-21604

    Last Modified: 15 Apr 2026

    LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2024-8474

    Last Modified: 10 Jun 2025

    OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic

    Published: 6 Jan 2025
    9.1
    Critical

    CVE-2024-5594

    Last Modified: 3 Nov 2025

    OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.

    Published: 6 Jan 2025
    3.9
    Low

    CVE-2024-12970

    Last Modified: 1 Jun 2026

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: before 0.7.2.

    Published: 6 Jan 2025
    5.5
    Medium

    CVE-2024-45559

    Last Modified: 28 Feb 2025

    Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2024-45558

    Last Modified: 11 Aug 2025

    Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.

    Published: 6 Jan 2025
    8.4
    High

    CVE-2024-45555

    Last Modified: 28 Feb 2025

    Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45553

    Last Modified: 26 Feb 2026

    Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45550

    Last Modified: 13 Jan 2025

    Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45548

    Last Modified: 13 Jan 2025

    Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45547

    Last Modified: 13 Jan 2025

    Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45546

    Last Modified: 13 Jan 2025

    Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45542

    Last Modified: 11 Aug 2025

    Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

    Published: 6 Jan 2025
    7.8
    High

    CVE-2024-45541

    Last Modified: 11 Aug 2025

    Memory corruption when IOCTL call is invoked from user-space to read board data.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2024-43064

    Last Modified: 28 Feb 2025

    Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.

    Published: 6 Jan 2025
    6.1
    Medium

    CVE-2024-43063

    Last Modified: 10 Jan 2025

    information disclosure while invoking the mailbox read API.

    Published: 6 Jan 2025
    6.1
    Medium

    CVE-2024-33067

    Last Modified: 11 Aug 2025

    Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

    Published: 6 Jan 2025
    6.8
    Medium

    CVE-2024-33061

    Last Modified: 10 Jan 2025

    Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.

    Published: 6 Jan 2025
    6.7
    Medium

    CVE-2024-33059

    Last Modified: 10 Jan 2025

    Memory corruption while processing frame command IOCTL calls.

    Published: 6 Jan 2025
    6.7
    Medium

    CVE-2024-33055

    Last Modified: 11 Aug 2025

    Memory corruption while invoking IOCTL calls to unmap the DMA buffers.

    Published: 6 Jan 2025
    6.7
    Medium

    CVE-2024-33041

    Last Modified: 11 Aug 2025

    Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,

    Published: 6 Jan 2025
    6.6
    Medium

    CVE-2024-23366

    Last Modified: 10 Jan 2025

    Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.

    Published: 6 Jan 2025
    8.4
    High

    CVE-2024-21464

    Last Modified: 26 Feb 2026

    Memory corruption while processing IPA statistics, when there are no active clients registered.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2024-20153

    Last Modified: 12 Jan 2026

    In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.

    Published: 6 Jan 2025
    4.4
    Medium

    CVE-2024-20152

    Last Modified: 21 Apr 2025

    In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.

    Published: 6 Jan 2025
    6.7
    Medium

    CVE-2024-20151

    Last Modified: 21 Apr 2025

    In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01399339; Issue ID: MSV-1928.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2024-20150

    Last Modified: 22 Apr 2025

    In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01412526; Issue ID: MSV-2018.

    Published: 6 Jan 2025
    7.5
    High

    CVE-2024-20149

    Last Modified: 12 Jan 2026

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01231341 / MOLY01263331 / MOLY01233835; Issue ID: MSV-2165.

    Published: 6 Jan 2025
    6.7
    Medium

    CVE-2024-20105

    Last Modified: 26 Feb 2026

    In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09062027; Issue ID: MSV-1743.

    Published: 6 Jan 2025
    9.8
    Critical

    CVE-2024-20148

    Last Modified: 26 Feb 2026

    In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.

    Published: 6 Jan 2025
    8.1
    High

    CVE-2024-20146

    Last Modified: 26 Feb 2026

    In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.

    Published: 6 Jan 2025
    6.6
    Medium

    CVE-2024-20145

    Last Modified: 22 Apr 2025

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.

    Published: 6 Jan 2025
    6.6
    Medium

    CVE-2024-20144

    Last Modified: 22 Apr 2025

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041.

    Published: 6 Jan 2025
    6.6
    Medium

    CVE-2024-20143

    Last Modified: 22 Apr 2025

    In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069.

    Published: 6 Jan 2025
    6.7
    Medium

    CVE-2024-20140

    Last Modified: 26 Feb 2026

    In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020.

    Published: 6 Jan 2025
    8.8
    High

    CVE-2024-20154

    Last Modified: 17 Feb 2026

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392.

    Published: 6 Jan 2025
    6.5
    Medium

    CVE-2024-12311

    Last Modified: 14 May 2025

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 6 Jan 2025
    6.1
    Medium

    CVE-2024-12302

    Last Modified: 14 May 2025

    The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks

    Published: 6 Jan 2025