CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-26025

    Last Modified: 6 Sept 2024

    Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    6.8
    Medium

    CVE-2023-43489

    Last Modified: 4 Feb 2025

    Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-23907

    Last Modified: 6 Sept 2024

    Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-21784

    Last Modified: 27 Aug 2025

    Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-28876

    Last Modified: 6 Sept 2024

    Uncontrolled search path for some Intel(R) MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-26027

    Last Modified: 6 Sept 2024

    Uncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-28172

    Last Modified: 6 Sept 2024

    Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    6.7
    Medium

    CVE-2024-25939

    Last Modified: 15 Apr 2026

    Mirrored regions with different values in 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.

    Published: 14 Aug 2024
    7.1
    High

    CVE-2024-28947

    Last Modified: 12 Sept 2024

    Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-29015

    Last Modified: 12 Sept 2024

    Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-28953

    Last Modified: 15 Apr 2026

    Uncontrolled search path in some EMON software before version 11.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-24977

    Last Modified: 12 Sept 2024

    Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-22184

    Last Modified: 4 Feb 2025

    Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-23489

    Last Modified: 12 Sept 2024

    Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-28887

    Last Modified: 12 Sept 2024

    Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    5.1
    Medium

    CVE-2024-28050

    Last Modified: 6 Sept 2024

    Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-27461

    Last Modified: 6 Sept 2024

    Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 Aug 2024
    8.5
    High

    CVE-2024-26022

    Last Modified: 6 Sept 2024

    Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39419

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    7.6
    High

    CVE-2024-39403

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Confidentiality impact is high due to the attacker being able to exfiltrate sensitive information.

    Published: 14 Aug 2024
    5.4
    Medium

    CVE-2024-39418

    Last Modified: 17 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures to view and edit low-sensitivity information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39413

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    7.7
    High

    CVE-2024-39399

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A low-privileged attacker could exploit this vulnerability to gain access to files and directories that are outside the restricted directory. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39408

    Last Modified: 16 Oct 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page that submits a malicious request. Exploitation of this issue requires user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39417

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39410

    Last Modified: 16 Oct 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page that submits a malicious request. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39407

    Last Modified: 17 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    7.4
    High

    CVE-2024-39398

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to perform brute force attacks and potentially gain unauthorized access to accounts. Exploitation of this issue does not require user interaction, but attack complexity is high.

    Published: 14 Aug 2024
    8.4
    High

    CVE-2024-39401

    Last Modified: 17 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed.

    Published: 14 Aug 2024
    9
    Critical

    CVE-2024-39397

    Last Modified: 16 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue does not require user interaction, but attack complexity is high and scope is changed.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39409

    Last Modified: 16 Oct 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. The vulnerability could be exploited by tricking a victim into clicking a link or loading a page that submits a malicious request. Exploitation of this issue requires user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39411

    Last Modified: 17 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39416

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39414

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39412

    Last Modified: 16 Oct 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and perform a minor integrity change. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    8.4
    High

    CVE-2024-39402

    Last Modified: 17 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed.

    Published: 14 Aug 2024
    6.8
    Medium

    CVE-2024-39406

    Last Modified: 16 Oct 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to gain access to files and directories that are outside the restricted directory. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 14 Aug 2024
    8.1
    High

    CVE-2024-39400

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a malicious link. Confidentiality and integrity impact is high as it affects other admin accounts.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39404

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39415

    Last Modified: 14 Aug 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    4.3
    Medium

    CVE-2024-39405

    Last Modified: 17 Sept 2024

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user interaction.

    Published: 14 Aug 2024
    6.4
    Medium

    CVE-2024-6532

    Last Modified: 15 Apr 2026

    The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Aug 2024
    5.8
    Medium

    CVE-2024-38483

    Last Modified: 18 Sept 2024

    Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

    Published: 14 Aug 2024
    8.8
    High

    CVE-2024-4389

    Last Modified: 15 Apr 2026

    The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with contributor access or higher, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 14 Aug 2024
    7.8
    High

    CVE-2024-41864

    Last Modified: 31 Aug 2024

    Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Aug 2024
    5.5
    Medium

    CVE-2024-41862

    Last Modified: 14 Aug 2024

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Aug 2024
    5.5
    Medium

    CVE-2024-41861

    Last Modified: 14 Aug 2024

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Aug 2024
    5.5
    Medium

    CVE-2024-41860

    Last Modified: 14 Aug 2024

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Aug 2024
    5.5
    Medium

    CVE-2024-41863

    Last Modified: 14 Aug 2024

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Aug 2024
    7.8
    High

    CVE-2024-41858

    Last Modified: 15 Oct 2024

    InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Aug 2024