CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-29780

    Last Modified: 18 Mar 2025

    In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    4.7
    Medium

    CVE-2024-29778

    Last Modified: 27 Mar 2025

    In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    6.9
    Medium

    CVE-2024-5976

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. Affected is the function log_employee of the file /classes/Master.php?f=log_employee. The manipulation of the argument employee_code leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268422 is the identifier assigned to this vulnerability.

    Published: 13 Jun 2024
    8.1
    High

    CVE-2024-32929

    Last Modified: 22 Jul 2025

    In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-4696

    Last Modified: 15 Apr 2026

    A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-38312

    Last Modified: 19 Aug 2026

    When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.

    Published: 13 Jun 2024
    4.3
    Medium

    CVE-2024-38313

    Last Modified: 19 Aug 2026

    In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-5947

    Last Modified: 21 Nov 2024

    Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22679.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-5948

    Last Modified: 21 Nov 2024

    Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of multipart boundaries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23170.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-5949

    Last Modified: 21 Nov 2024

    Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of multipart boundaries. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23171.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-5950

    Last Modified: 21 Nov 2024

    Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of multipart form variables. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23172.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-5951

    Last Modified: 21 Nov 2024

    Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-5952

    Last Modified: 21 Nov 2024

    Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23174.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-5924

    Last Modified: 23 Nov 2024

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of shared folders. When syncing files from a shared folder belonging to an untrusted account, the Dropbox desktop application does not apply the Mark-of-the-Web to the local files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-23991.

    Published: 13 Jun 2024
    4.3
    Medium

    CVE-2024-38083

    Last Modified: 17 Dec 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-30057

    Last Modified: 17 Dec 2025

    Microsoft Edge for iOS Spoofing Vulnerability

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-30058

    Last Modified: 17 Dec 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 13 Jun 2024
    7
    High

    CVE-2024-38285

    Last Modified: 15 Apr 2026

    Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.

    Published: 13 Jun 2024
    8.5
    High

    CVE-2024-37022

    Last Modified: 21 Nov 2024

    Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipulate memory, resulting in execution of arbitrary code.

    Published: 13 Jun 2024
    8.5
    High

    CVE-2024-37029

    Last Modified: 21 Nov 2024

    Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-0086

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.

    Published: 13 Jun 2024
    6.3
    Medium

    CVE-2024-0085

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-0084

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-0092

    Last Modified: 21 Nov 2024

    NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-0093

    Last Modified: 21 Nov 2024

    NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-0091

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-0089

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-0090

    Last Modified: 21 Nov 2024

    NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 13 Jun 2024
    8.7
    High

    CVE-2024-38284

    Last Modified: 15 Apr 2026

    Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.

    Published: 13 Jun 2024
    5.1
    Medium

    CVE-2024-38283

    Last Modified: 15 Apr 2026

    Sensitive customer information is stored in the device without encryption.

    Published: 13 Jun 2024
    8.5
    High

    CVE-2024-38282

    Last Modified: 15 Apr 2026

    Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requiring a physical reboot of the system.

    Published: 13 Jun 2024
    8.6
    High

    CVE-2024-38281

    Last Modified: 21 Nov 2024

    An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

    Published: 13 Jun 2024
    7
    High

    CVE-2024-38280

    Last Modified: 21 Nov 2024

    An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

    Published: 13 Jun 2024
    5.1
    Medium

    CVE-2024-38279

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

    Published: 13 Jun 2024
    7.9
    High

    CVE-2024-37307

    Last Modified: 9 Jan 2025

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitive data when the tool is run (with the `--envoy-dump` flag set) against Cilium deployments with the Envoy proxy enabled. Users of the TLS inspection, Ingress with TLS termination, Gateway API with TLS termination, and Kafka network policies with API key filtering features are affected. The sensitive data includes the CA certificate, certificate chain, and private key used by Cilium HTTP Network Policies, and when using Ingress/Gateway API and the API keys used in Kafka-related network policy. `cilium-bugtool` is a debugging tool that is typically invoked manually and does not run during the normal operation of a Cilium cluster. This issue has been patched in Cilium v1.15.6, v1.14.12, and v1.13.17. There is no workaround to this issue.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-22441

    Last Modified: 25 Mar 2025

    HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-29169

    Last Modified: 30 Sept 2025

    Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-29168

    Last Modified: 21 Nov 2024

    Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data.

    Published: 13 Jun 2024
    4.3
    Medium

    CVE-2024-28969

    Last Modified: 21 Nov 2024

    Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-28968

    Last Modified: 21 Nov 2024

    Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-28967

    Last Modified: 21 Nov 2024

    Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-28966

    Last Modified: 21 Nov 2024

    Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-28965

    Last Modified: 21 Nov 2024

    Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain Internal APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-37131

    Last Modified: 20 May 2025

    SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the application in the context of the authenticated user.

    Published: 13 Jun 2024
    7.1
    High

    CVE-2024-37306

    Last Modified: 21 Jan 2025

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they can initiate a dataset export or a backup from a project, task or job that the victim user has permission to export into a cloud storage that the victim user has access to. The name of the resulting file can be chosen by the attacker. This implies that the attacker can overwrite arbitrary files in any cloud storage that the victim can access and, if the attacker has read access to the cloud storage used in the attack, they can obtain media files, annotations, settings and other information from any projects, tasks or jobs that the victim has permission to export. Version 2.14.3 contains a fix for the issue. No known workarounds are available.

    Published: 13 Jun 2024
    —
    Unknown

    CVE-2024-5972

    Last Modified: 28 Jun 2024

    CVE ID issued in error. This is not a valid vulnerability.

    Published: 13 Jun 2024
    7.1
    High

    CVE-2024-37164

    Last Modified: 21 Jan 2025

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob Storage. Starting in version 2.1.0 and prior to version 2.14.3, an attacker with a CVAT account can exploit this feature by specifying URLs whose host part is an intranet IP address or an internal domain name. By doing this, the attacker may be able to probe the network that the CVAT backend runs in for HTTP(S) servers. In addition, if there is a web server on this network that is sufficiently API-compatible with an Amazon S3 or Azure Blob Storage endpoint, and either allows anonymous access, or allows authentication with credentials that are known by the attacker, then the attacker may be able to create a cloud storage linked to this server. They may then be able to list files on the server; extract files from the server, if these files are of a type that CVAT supports reading from cloud storage (media data (such as images/videos/archives), importable annotations or datasets, task/project backups); and/or overwrite files on this server with exported annotations/datasets/backups. The exact capabilities of the attacker will depend on how the internal server is configured. Users should upgrade to CVAT 2.14.3 to receive a patch. In this release, the existing SSRF mitigation measures are applied to requests to cloud providers, with access to intranet IP addresses prohibited by default. Some workarounds are also available. One may use network security solutions such as virtual networks or firewalls to prohibit network access from the CVAT backend to unrelated servers on your internal network and/or require authentication for access to internal servers.

    Published: 13 Jun 2024
    5.3
    Medium

    CVE-2024-37309

    Last Modified: 4 Sept 2025

    CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated renegotiation. In this scenario, an attacker can exploit this feature to repeatedly request renegotiation of security parameters during an ongoing TLS session. This flaw could lead to excessive consumption of CPU resources, resulting in potential server overload and service disruption. The vulnerability was confirmed using an openssl client where the command `R` initiates renegotiation, followed by the server confirming with `RENEGOTIATING`. This vulnerability allows an attacker to perform a denial of service attack by exhausting server CPU resources through repeated TLS renegotiations. This impacts the availability of services running on the affected server, posing a significant risk to operational stability and security. TLS 1.3 explicitly forbids renegotiation, since it closes a window of opportunity for an attack. Version 5.7.2 of CrateDB contains the fix for the issue.

    Published: 13 Jun 2024
    3.3
    Low

    CVE-2024-22333

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-37308

    Last Modified: 11 Feb 2025

    The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. A patch is available at commit 8cf88f334ccbf11134080bbb655c66f1cfe77026 and will be part of version 1.8.0.

    Published: 13 Jun 2024