CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-38063

    Last Modified: 10 Jul 2025

    Windows TCP/IP Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38084

    Last Modified: 10 Jul 2025

    Microsoft OfficePlus Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    6.5
    Medium

    CVE-2024-38213

    Last Modified: 28 Oct 2025

    Windows Mark of the Web Security Feature Bypass Vulnerability

    Published: 13 Aug 2024
    7
    High

    CVE-2024-38201

    Last Modified: 10 Jul 2025

    Azure Stack Hub Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    9.8
    Critical

    CVE-2024-38199

    Last Modified: 10 Jul 2025

    Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    7.5
    High

    CVE-2024-38198

    Last Modified: 10 Jul 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    6.5
    Medium

    CVE-2024-38197

    Last Modified: 10 Jul 2025

    Microsoft Teams for iOS Spoofing Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38196

    Last Modified: 10 Jul 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38193

    Last Modified: 28 Oct 2025

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38191

    Last Modified: 10 Jul 2025

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38184

    Last Modified: 10 Jul 2025

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    7.5
    High

    CVE-2024-38178

    Last Modified: 28 Oct 2025

    Scripting Engine Memory Corruption Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38172

    Last Modified: 10 Jul 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    6.8
    Medium

    CVE-2024-38161

    Last Modified: 10 Jul 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    9.1
    Critical

    CVE-2024-38160

    Last Modified: 10 Jul 2025

    Windows Network Virtualization Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    9.1
    Critical

    CVE-2024-38159

    Last Modified: 10 Jul 2025

    Windows Network Virtualization Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    4.4
    Medium

    CVE-2024-38123

    Last Modified: 10 Jul 2025

    Windows Bluetooth Driver Information Disclosure Vulnerability

    Published: 13 Aug 2024
    9.3
    Critical

    CVE-2024-38108

    Last Modified: 10 Jul 2025

    Azure Stack Hub Spoofing Vulnerability

    Published: 13 Aug 2024
    3.3
    Low

    CVE-2023-31366

    Last Modified: 12 Dec 2024

    Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.

    Published: 13 Aug 2024
    7.3
    High

    CVE-2023-31349

    Last Modified: 12 Dec 2024

    Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 13 Aug 2024
    7.3
    High

    CVE-2023-31348

    Last Modified: 12 Dec 2024

    A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 13 Aug 2024
    7.3
    High

    CVE-2023-31341

    Last Modified: 26 Feb 2025

    Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.

    Published: 13 Aug 2024
    4.8
    Medium

    CVE-2023-31339

    Last Modified: 5 Jun 2026

    Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

    Published: 13 Aug 2024
    5.7
    Medium

    CVE-2024-21981

    Last Modified: 15 Apr 2026

    Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.

    Published: 13 Aug 2024
    5
    Medium

    CVE-2023-31310

    Last Modified: 15 Apr 2026

    Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

    Published: 13 Aug 2024
    2.3
    Low

    CVE-2023-31307

    Last Modified: 13 Dec 2024

    Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.

    Published: 13 Aug 2024
    2.3
    Low

    CVE-2023-31304

    Last Modified: 15 Apr 2026

    Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to modify the PCIe® lane count and speed, potentially leading to a loss of availability.

    Published: 13 Aug 2024
    1.9
    Low

    CVE-2023-31305

    Last Modified: 15 Apr 2026

    Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.

    Published: 13 Aug 2024
    6.5
    Medium

    CVE-2023-20591

    Last Modified: 13 Mar 2025

    Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

    Published: 13 Aug 2024
    7.5
    High

    CVE-2023-20578

    Last Modified: 18 Mar 2025

    A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.

    Published: 13 Aug 2024
    1.9
    Low

    CVE-2023-20518

    Last Modified: 15 Apr 2026

    Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.

    Published: 13 Aug 2024
    3.3
    Low

    CVE-2023-20513

    Last Modified: 15 Apr 2026

    An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.

    Published: 13 Aug 2024
    1.9
    Low

    CVE-2023-20512

    Last Modified: 15 Apr 2026

    A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.

    Published: 13 Aug 2024
    4.7
    Medium

    CVE-2023-20510

    Last Modified: 12 Dec 2024

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

    Published: 13 Aug 2024
    5.2
    Medium

    CVE-2023-20509

    Last Modified: 15 Apr 2026

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.

    Published: 13 Aug 2024
    7.3
    High

    CVE-2022-23817

    Last Modified: 15 May 2026

    Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.

    Published: 13 Aug 2024
    7.5
    High

    CVE-2022-23815

    Last Modified: 18 Mar 2025

    Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.

    Published: 13 Aug 2024
    3.9
    Low

    CVE-2021-46772

    Last Modified: 15 Apr 2026

    Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure headers in SPI ROM causing an out of bounds memory read and write, potentially resulting in memory corruption or denial of service.

    Published: 13 Aug 2024
    5.2
    Medium

    CVE-2021-46746

    Last Modified: 15 Apr 2026

    Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.

    Published: 13 Aug 2024
    3.9
    Low

    CVE-2021-26387

    Last Modified: 15 Apr 2026

    Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.

    Published: 13 Aug 2024
    5.7
    Medium

    CVE-2021-26367

    Last Modified: 12 Dec 2024

    A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.

    Published: 13 Aug 2024
    7.2
    High

    CVE-2021-26344

    Last Modified: 18 Mar 2025

    An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

    Published: 13 Aug 2024
    8.5
    High

    CVE-2024-6619

    Last Modified: 15 Apr 2026

    In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.

    Published: 13 Aug 2024
    8.5
    High

    CVE-2024-6618

    Last Modified: 15 Apr 2026

    In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).

    Published: 13 Aug 2024
    8.7
    High

    CVE-2024-7113

    Last Modified: 15 Apr 2026

    If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.

    Published: 13 Aug 2024
    6.1
    Medium

    CVE-2024-21757

    Last Modified: 22 Aug 2024

    A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.

    Published: 13 Aug 2024
    6.6
    Medium

    CVE-2022-27486

    Last Modified: 22 Aug 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 through 6.3.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 allows an authenticated attacker to execute shell code as `root` via `execute` CLI commands.

    Published: 13 Aug 2024
    3.7
    Low

    CVE-2022-45862

    Last Modified: 22 Aug 2024

    An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials.

    Published: 13 Aug 2024
    5.1
    Medium

    CVE-2024-36505

    Last Modified: 22 Aug 2024

    An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.

    Published: 13 Aug 2024
    6.8
    Medium

    CVE-2023-26211

    Last Modified: 22 Aug 2024

    An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.

    Published: 13 Aug 2024