CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-5688

    Last Modified: 4 Apr 2025

    If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

    Published: 11 Jun 2024
    4.7
    Medium

    CVE-2024-5691

    Last Modified: 19 Mar 2025

    By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

    Published: 11 Jun 2024
    6.1
    Medium

    CVE-2024-5693

    Last Modified: 27 Mar 2025

    Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

    Published: 11 Jun 2024
    2.7
    Low

    CVE-2024-22261

    Last Modified: 21 Nov 2024

    SQL-Injection in Harbor allows priviledge users to leak the task IDs

    Published: 10 Jun 2024
    4.3
    Medium

    CVE-2024-22244

    Last Modified: 26 Feb 2025

    Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

    Published: 10 Jun 2024
    6.8
    Medium

    CVE-2022-37020

    Last Modified: 13 Feb 2026

    Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

    Published: 10 Jun 2024
    6.8
    Medium

    CVE-2022-37019

    Last Modified: 14 Jan 2026

    Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

    Published: 10 Jun 2024
    7.5
    High

    CVE-2024-36471

    Last Modified: 15 Jul 2025

    Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allura from 1.0.1 through 1.16.0. Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file.

    Published: 10 Jun 2024
    5.3
    Medium

    CVE-2024-37169

    Last Modified: 15 Apr 2026

    @jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Playright's screenshot feature to exploit the file wrapper. Version 2.0.3 mitigates this issue by requiring input URLs to be of protocol `http` or `https`. No known workarounds are available aside from upgrading.

    Published: 10 Jun 2024
    8.9
    High

    CVE-2024-37166

    Last Modified: 15 Apr 2026

    ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) vulnerability in some cases. Version 2.0.0 introduces changes to mitigate this issue. Version 2.0.0 contains updated documentation to clarify that while ghtml escapes characters with special meaning in HTML, it does not provide comprehensive protection against all types of XSS attacks in every scenario. This aligns with the approach taken by other template engines. Developers should be cautious and take additional measures to sanitize user input and prevent potential vulnerabilities. Additionally, the backtick character (`) is now also escaped to prevent the creation of strings in most cases where a malicious actor somehow gains the ability to write JavaScript. This does not provide comprehensive protection either.

    Published: 10 Jun 2024
    —
    Unknown

    CVE-2024-5825

    Last Modified: 11 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-35242

    Last Modified: 15 Apr 2026

    Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-37289

    Last Modified: 16 Jun 2025

    An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    5.3
    Medium

    CVE-2024-36473

    Last Modified: 30 Jul 2025

    Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under specific conditions can lead to elevation of privileges.

    Published: 10 Jun 2024
    5.4
    Medium

    CVE-2024-36359

    Last Modified: 18 Mar 2025

    A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-36358

    Last Modified: 23 Oct 2025

    A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    4.7
    Medium

    CVE-2024-36307

    Last Modified: 27 Jun 2025

    A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    6.1
    Medium

    CVE-2024-36306

    Last Modified: 27 Mar 2025

    A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to create a denial-of-service condition on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-36305

    Last Modified: 14 Mar 2025

    A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-36304

    Last Modified: 16 Jun 2025

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-36303

    Last Modified: 25 Mar 2025

    An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to, but not identical to, CVE-2024-36302.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-36302

    Last Modified: 29 May 2025

    An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to, but not identical to, CVE-2024-36303.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-35241

    Last Modified: 15 Apr 2026

    Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-32849

    Last Modified: 30 Jul 2025

    Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

    Published: 10 Jun 2024
    4.3
    Medium

    CVE-2024-36419

    Last Modified: 21 Nov 2024

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.

    Published: 10 Jun 2024
    6.5
    Medium

    CVE-2024-27830

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-27851

    Last Modified: 2 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 10 Jun 2024
    5.5
    Medium

    CVE-2024-27806

    Last Modified: 2 Apr 2026

    This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to access sensitive user data.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27811

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.

    Published: 10 Jun 2024
    4.3
    Medium

    CVE-2024-27807

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5. An app may be able to circumvent App Privacy Report logging.

    Published: 10 Jun 2024
    6.5
    Medium

    CVE-2024-27850

    Last Modified: 2 Apr 2026

    This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.

    Published: 10 Jun 2024
    6.3
    Medium

    CVE-2024-27885

    Last Modified: 2 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to modify protected parts of the file system.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27831

    Last Modified: 2 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27857

    Last Modified: 2 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.

    Published: 10 Jun 2024
    6.5
    Medium

    CVE-2024-27800

    Last Modified: 2 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a maliciously crafted message may lead to a denial-of-service.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27836

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-27820

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.

    Published: 10 Jun 2024
    6.3
    Medium

    CVE-2024-27840

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27817

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27801

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.

    Published: 10 Jun 2024
    2.4
    Low

    CVE-2024-27814

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27802

    Last Modified: 2 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-27855

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. A shortcut may be able to use sensitive data with certain actions without prompting the user.

    Published: 10 Jun 2024
    6.5
    Medium

    CVE-2024-27838

    Last Modified: 2 Apr 2026

    The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.

    Published: 10 Jun 2024
    4.6
    Medium

    CVE-2024-23251

    Last Modified: 2 Apr 2026

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. An attacker with physical access may be able to leak Mail account credentials.

    Published: 10 Jun 2024
    2.4
    Low

    CVE-2024-27819

    Last Modified: 2 Apr 2026

    The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27815

    Last Modified: 2 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.

    Published: 10 Jun 2024
    3.3
    Low

    CVE-2024-27799

    Last Modified: 2 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-27808

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.

    Published: 10 Jun 2024
    7.8
    High

    CVE-2024-27832

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.

    Published: 10 Jun 2024