CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2024-23384

    Last Modified: 26 Nov 2024

    Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-23383

    Last Modified: 26 Nov 2024

    Memory corruption when kernel driver attempts to trigger hardware fences.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-23382

    Last Modified: 26 Nov 2024

    Memory corruption while processing graphics kernel driver request to create DMA fence.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-23381

    Last Modified: 26 Nov 2024

    Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.

    Published: 5 Aug 2024
    6.2
    Medium

    CVE-2024-23357

    Last Modified: 25 Nov 2024

    Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-23356

    Last Modified: 26 Nov 2024

    Memory corruption during session sign renewal request calls in HLOS.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-23355

    Last Modified: 26 Nov 2024

    Memory corruption when keymaster operation imports a shared key.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-23353

    Last Modified: 26 Nov 2024

    Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-23352

    Last Modified: 26 Nov 2024

    Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

    Published: 5 Aug 2024
    6.5
    Medium

    CVE-2024-23350

    Last Modified: 26 Nov 2024

    Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-21481

    Last Modified: 11 Aug 2025

    Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-21479

    Last Modified: 26 Nov 2024

    Transient DOS during music playback of ALAC content.

    Published: 5 Aug 2024
    6.5
    Medium

    CVE-2024-21467

    Last Modified: 26 Nov 2024

    Information disclosure while handling beacon probe frame during scan entry generation in client side.

    Published: 5 Aug 2024
    6.5
    Medium

    CVE-2024-21459

    Last Modified: 15 Aug 2025

    Information disclosure while handling beacon or probe response frame in STA.

    Published: 5 Aug 2024
    9.3
    Critical

    CVE-2024-7397

    Last Modified: 15 Apr 2026

    Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.

    Published: 5 Aug 2024
    7.1
    High

    CVE-2024-7396

    Last Modified: 15 Apr 2026

    Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.

    Published: 5 Aug 2024
    9.3
    Critical

    CVE-2024-7395

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-4607

    Last Modified: 30 Sept 2024

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p0; Valhall GPU Kernel Driver: from r41p0 through r49p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p0.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-2937

    Last Modified: 30 Sept 2024

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p0; Valhall GPU Kernel Driver: from r41p0 through r49p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p0.

    Published: 5 Aug 2024
    7.3
    High

    CVE-2024-36448

    Last Modified: 13 Mar 2025

    ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 5 Aug 2024
    9.8
    Critical

    CVE-2024-38856

    Last Modified: 23 Oct 2025

    Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

    Published: 5 Aug 2024
    9.8
    Critical

    CVE-2024-42447

    Last Modified: 19 Mar 2025

    Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out.   * FAB provider 1.2.1 only affected Airflow 2.9.3 (earlier and later versions of Airflow are not affected) * FAB provider 1.2.0 affected all versions of Airflow. Users who run Apache Airflow 2.9.3 are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue. Users who run Any Apache Airflow version and have FAB provider 1.2.0 are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue. Also upgrading Apache Airflow to latest version available is recommended. Note: Early version of Airflow reference container images of Airflow 2.9.3 and constraint files contained FAB provider 1.2.1 version, but this is fixed in updated versions of the images.  Users are advised to pull the latest Airflow images or reinstall FAB provider according to the current constraints.

    Published: 5 Aug 2024
    5.4
    Medium

    CVE-2024-6710

    Last Modified: 5 Sept 2024

    The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

    Published: 5 Aug 2024
    4.8
    Medium

    CVE-2024-6498

    Last Modified: 6 Sept 2024

    The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 5 Aug 2024
    4.8
    Medium

    CVE-2024-6270

    Last Modified: 12 Jun 2025

    The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 5 Aug 2024
    6.1
    Medium

    CVE-2024-5081

    Last Modified: 9 Jun 2025

    The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 5 Aug 2024
    5.4
    Medium

    CVE-2024-3636

    Last Modified: 6 Jun 2025

    The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 5 Aug 2024
    8.1
    High

    CVE-2024-2232

    Last Modified: 2 Jan 2026

    The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

    Published: 5 Aug 2024
    9.8
    Critical

    CVE-2024-41889

    Last Modified: 30 Aug 2024

    Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.

    Published: 5 Aug 2024
    8
    High

    CVE-2024-41720

    Last Modified: 17 Mar 2025

    Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the configuration of the device.

    Published: 5 Aug 2024
    8.8
    High

    CVE-2024-39838

    Last Modified: 25 Mar 2025

    ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.

    Published: 5 Aug 2024
    8.6
    High

    CVE-2024-39713

    Last Modified: 6 Sept 2024

    A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

    Published: 5 Aug 2024
    9.3
    Critical

    CVE-2024-6118

    Last Modified: 30 Aug 2024

    A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.

    Published: 5 Aug 2024
    9.3
    Critical

    CVE-2024-6117

    Last Modified: 30 Aug 2024

    A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

    Published: 5 Aug 2024
    5.3
    Medium

    CVE-2024-7470

    Last Modified: 6 Aug 2024

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of the file /vpn/vpn_template_style.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273563. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    5.3
    Medium

    CVE-2024-7469

    Last Modified: 6 Aug 2024

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of the file /vpn/list_vpn_web_custom.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273562 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    5.3
    Medium

    CVE-2024-7468

    Last Modified: 6 Aug 2024

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the file /vpn/list_service_manage.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273561 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    5.3
    Medium

    CVE-2024-7467

    Last Modified: 6 Aug 2024

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of the file /vpn/list_ip_network.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273560. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    5.1
    Medium

    CVE-2024-7466

    Last Modified: 6 Aug 2024

    A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Application Firewall. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273559. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    8.7
    High

    CVE-2024-7465

    Last Modified: 15 Aug 2024

    A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273558 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    5.3
    Medium

    CVE-2024-7464

    Last Modified: 15 Aug 2024

    A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. The manipulation of the argument telnet_enabled leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273557 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    8.7
    High

    CVE-2024-7463

    Last Modified: 15 Aug 2024

    A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273556. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    8.7
    High

    CVE-2024-7462

    Last Modified: 15 Aug 2024

    A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273555. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Aug 2024
    8.8
    High

    CVE-2024-40531

    Last Modified: 15 Apr 2026

    A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions.

    Published: 5 Aug 2024
    6
    Medium

    CVE-2024-21978

    Last Modified: 26 Nov 2024

    Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

    Published: 5 Aug 2024
    7.9
    High

    CVE-2024-21980

    Last Modified: 26 Nov 2024

    Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

    Published: 5 Aug 2024
    3.3
    Low

    CVE-2024-40096

    Last Modified: 28 Oct 2024

    The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.

    Published: 5 Aug 2024
    5.5
    Medium

    CVE-2024-41200

    Last Modified: 18 Jun 2025

    A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

    Published: 5 Aug 2024
    8.8
    High

    CVE-2024-41376

    Last Modified: 20 Nov 2025

    dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

    Published: 5 Aug 2024
    6.1
    Medium

    CVE-2024-41380

    Last Modified: 10 Jul 2025

    microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

    Published: 5 Aug 2024