CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-36504

    Last Modified: 26 Dec 2024

    Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.

    Published: 13 Jun 2024
    6.3
    Medium

    CVE-2023-36694

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2023-36695

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

    Published: 13 Jun 2024
    5.3
    Medium

    CVE-2023-37394

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-0094

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to denial of service.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-0099

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could cause buffer overrun in the host. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.

    Published: 13 Jun 2024
    9
    Critical

    CVE-2024-0095

    Last Modified: 26 Sept 2025

    NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-0103

    Last Modified: 26 Sept 2025

    NVIDIA Triton Inference Server for Linux contains a vulnerability where a user may cause an incorrect Initialization of resource by network issue. A successful exploit of this vulnerability may lead to information disclosure.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-32930

    Last Modified: 22 Jul 2025

    In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-32926

    Last Modified: 22 Jul 2025

    there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-32925

    Last Modified: 22 Jul 2025

    In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-32924

    Last Modified: 22 Jul 2025

    In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    4
    Medium

    CVE-2024-32923

    Last Modified: 22 Jul 2025

    there is a possible cellular denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.4
    High

    CVE-2024-32922

    Last Modified: 22 Jul 2025

    In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.4
    High

    CVE-2024-32921

    Last Modified: 22 Jul 2025

    In lwis_initialize_transaction_fences of lwis_fence.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.1
    High

    CVE-2024-32920

    Last Modified: 22 Jul 2025

    In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32919

    Last Modified: 22 Jul 2025

    In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    6.1
    Medium

    CVE-2024-32918

    Last Modified: 21 Nov 2024

    Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps

    Published: 13 Jun 2024
    7.1
    High

    CVE-2024-32917

    Last Modified: 24 Jul 2025

    In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.9
    Medium

    CVE-2024-32916

    Last Modified: 24 Jul 2025

    In fvp_freq_histogram_init of fvp.c, there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    4.3
    Medium

    CVE-2024-32915

    Last Modified: 24 Jul 2025

    In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-32914

    Last Modified: 24 Jul 2025

    In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-32913

    Last Modified: 21 Nov 2024

    In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-32912

    Last Modified: 20 Mar 2025

    there is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of service of impaired use of the device with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-32911

    Last Modified: 21 Nov 2024

    There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-32910

    Last Modified: 13 Mar 2025

    In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32909

    Last Modified: 21 Nov 2024

    In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32908

    Last Modified: 21 Nov 2024

    In sec_media_protect of media.c, there is a possible permission bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32907

    Last Modified: 21 Nov 2024

    In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32906

    Last Modified: 21 Nov 2024

    In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-32905

    Last Modified: 21 Nov 2024

    In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    4.7
    Medium

    CVE-2024-32904

    Last Modified: 13 Mar 2025

    In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32903

    Last Modified: 21 Nov 2024

    In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-32902

    Last Modified: 26 Feb 2026

    Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32901

    Last Modified: 24 Mar 2025

    In v4l2_smfc_qbuf of smfc-v4l2-ioctls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32900

    Last Modified: 21 Nov 2024

    In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of privilege from hal_camera_default SELinux label with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7
    High

    CVE-2024-32899

    Last Modified: 21 Nov 2024

    In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    4.7
    Medium

    CVE-2024-32898

    Last Modified: 13 Mar 2025

    In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.9
    Medium

    CVE-2024-32897

    Last Modified: 13 Mar 2025

    In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32896

    Last Modified: 24 Oct 2025

    there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32895

    Last Modified: 21 Nov 2024

    In BCMFASTPATH of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-32894

    Last Modified: 27 Mar 2025

    In bc_get_converted_received_bearer of bc_utilities.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-32893

    Last Modified: 21 Nov 2024

    In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-32892

    Last Modified: 13 Mar 2025

    In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7
    High

    CVE-2024-32891

    Last Modified: 21 Nov 2024

    In sec_media_unprotect of media.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-29787

    Last Modified: 21 Nov 2024

    In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-29786

    Last Modified: 21 Nov 2024

    In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-29785

    Last Modified: 18 Mar 2025

    In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-29784

    Last Modified: 21 Nov 2024

    In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-29781

    Last Modified: 21 Nov 2024

    In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024