CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2024-21772

    Last Modified: 27 Aug 2025

    Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    4.4
    Medium

    CVE-2024-22390

    Last Modified: 15 Apr 2026

    Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.

    Published: 16 May 2024
    5.7
    Medium

    CVE-2023-49614

    Last Modified: 15 Apr 2026

    Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclosure.

    Published: 16 May 2024
    7.8
    High

    CVE-2024-21864

    Last Modified: 15 Apr 2026

    Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21774

    Last Modified: 15 Apr 2026

    Uncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21862

    Last Modified: 28 Jan 2025

    Uncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21777

    Last Modified: 28 Jan 2025

    Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21809

    Last Modified: 28 Jan 2025

    Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21837

    Last Modified: 28 Jan 2025

    Uncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21828

    Last Modified: 15 Apr 2026

    Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21843

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) Computing Improvement Program software before version 2.4.0.10654 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21835

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21788

    Last Modified: 23 Jan 2025

    Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21861

    Last Modified: 23 Jan 2025

    Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    6.7
    Medium

    CVE-2024-21831

    Last Modified: 27 Aug 2025

    Uncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 May 2024
    5.8
    Medium

    CVE-2023-22662

    Last Modified: 15 Apr 2026

    Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potentially enable denial of service via local access.

    Published: 16 May 2024
    7.2
    High

    CVE-2024-22095

    Last Modified: 15 Apr 2026

    Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-23980

    Last Modified: 15 Apr 2026

    Improper buffer restrictions in PlatformPfrDxe driver in UEFI firmware for some Intel(R) Server D50FCP Family products may allow a privileged user to enable escalation of privilege via local access.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-24981

    Last Modified: 15 Apr 2026

    Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to enable escalation of privilege via local access.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-23487

    Last Modified: 15 Apr 2026

    Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-22382

    Last Modified: 15 Apr 2026

    Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.

    Published: 16 May 2024
    4.7
    Medium

    CVE-2024-21792

    Last Modified: 15 Apr 2026

    Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 16 May 2024
    10
    Critical

    CVE-2024-22476

    Last Modified: 15 Apr 2026

    Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

    Published: 16 May 2024
    4.3
    Medium

    CVE-2024-3609

    Last Modified: 8 Apr 2026

    The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.

    Published: 16 May 2024
    5
    Medium

    CVE-2024-2619

    Last Modified: 8 Apr 2026

    The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.

    Published: 16 May 2024
    4.3
    Medium

    CVE-2024-4204

    Last Modified: 15 Apr 2026

    The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-4733

    Last Modified: 15 Apr 2026

    The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenticated attacker with contributor access-level or above to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 16 May 2024
    4.9
    Medium

    CVE-2024-31226

    Last Modified: 11 Sept 2025

    Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named `C:\Program.exe`, `C:\Program.bat`, or `C:\Program.cmd` on the user's computer. This attack vector isn't exploitable unless the user has manually loosened ACLs on the system drive. If the user's system locale is not English, then the name of the executable will likely vary. Version 0.23.0 contains a patch for the issue. Some workarounds are available. One may identify and block potentially malicious software executed path interception by using application control tools, like Windows Defender Application Control, AppLocker, or Software Restriction Policies where appropriate. Alternatively, ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory `C:`. Require that all executables be placed in write-protected directories.

    Published: 16 May 2024
    9.3
    Critical

    CVE-2024-5023

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.

    Published: 16 May 2024
    7.8
    High

    CVE-2024-1417

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for MacOS versions before 1.0.6.

    Published: 16 May 2024
    4.4
    Medium

    CVE-2023-47717

    Last Modified: 13 Jun 2025

    IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-3286

    Last Modified: 15 Apr 2026

    A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.

    Published: 16 May 2024
    8.4
    High

    CVE-2024-27260

    Last Modified: 29 Jul 2025

    IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.

    Published: 16 May 2024
    9.8
    Critical

    CVE-2023-48643

    Last Modified: 15 Apr 2026

    Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.

    Published: 16 May 2024
    6.5
    Medium

    CVE-2024-34760

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.

    Published: 16 May 2024
    6.5
    Medium

    CVE-2024-34805

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webvitaly iFrame allows Stored XSS.This issue affects iFrame: from n/a through 5.0.

    Published: 16 May 2024
    4.4
    Medium

    CVE-2024-34751

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.

    Published: 16 May 2024
    4.3
    Medium

    CVE-2024-34808

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-4956

    Last Modified: 15 Apr 2026

    Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.

    Published: 16 May 2024
    7
    High

    CVE-2024-3640

    Last Modified: 15 Apr 2026

    An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.

    Published: 16 May 2024
    9.1
    Critical

    CVE-2024-35187

    Last Modified: 15 Apr 2026

    Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user (not as root) to isolate an attacker with Arbitrary Code Execution to the current service. Therefore, other system services and the system itself remains protected in case of a successful attack. stalwart-mail runs as a separate user, but it can give itself full privileges again in a simple way, so this protection is practically ineffective. Server admins who handed out the admin credentials to the mail server, but didn't want to hand out complete root access to the system, as well as any attacked user when the attackers gained Arbitrary Code Execution using another vulnerability, may be vulnerable. Version 0.8.0 contains a patch for the issue.

    Published: 16 May 2024
    5.9
    Medium

    CVE-2024-34273

    Last Modified: 15 Apr 2026

    njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.

    Published: 16 May 2024
    5.3
    Medium

    CVE-2024-35185

    Last Modified: 15 Apr 2026

    Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder server. The REST ingester allows users to interact with REST endpoints to fetch data for rule evaluation. When fetching data with the REST ingester, Minder sends a request to an endpoint and will use the data from the body of the response as the data to evaluate against a certain rule. If the response is sufficiently large, it can drain memory on the machine and crash the Minder server. The attacker can control the remote REST endpoints that Minder sends requests to, and they can configure the remote REST endpoints to return responses with large bodies. They would then instruct Minder to send a request to their configured endpoint that would return the large response which would crash the Minder server. Version 0.0.49 fixes this issue.

    Published: 16 May 2024
    8.8
    High

    CVE-2024-4609

    Last Modified: 30 Jan 2025

    A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.

    Published: 16 May 2024
    —
    Unknown

    CVE-2024-5007

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 May 2024
    5.4
    Medium

    CVE-2024-34957

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.

    Published: 16 May 2024
    6.5
    Medium

    CVE-2024-34958

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add

    Published: 16 May 2024
    3.8
    Low

    CVE-2024-35039

    Last Modified: 15 Apr 2025

    idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.

    Published: 16 May 2024
    6.1
    Medium

    CVE-2024-34582

    Last Modified: 15 Apr 2026

    Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

    Published: 16 May 2024
    7.5
    High

    CVE-2024-34905

    Last Modified: 13 Feb 2025

    FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 16 May 2024