CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-4138

    Last Modified: 15 Apr 2026

    Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

    Published: 14 May 2024
    4.3
    Medium

    CVE-2024-4139

    Last Modified: 15 Apr 2026

    Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

    Published: 14 May 2024
    8.1
    High

    CVE-2024-28165

    Last Modified: 16 Dec 2025

    SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application

    Published: 14 May 2024
    6.1
    Medium

    CVE-2024-33002

    Last Modified: 15 Apr 2026

    Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.

    Published: 14 May 2024
    3.5
    Low

    CVE-2024-33000

    Last Modified: 15 Apr 2026

    SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.

    Published: 14 May 2024
    4.9
    Medium

    CVE-2024-33008

    Last Modified: 15 Apr 2026

    SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.

    Published: 14 May 2024
    3.5
    Low

    CVE-2024-33007

    Last Modified: 15 Apr 2026

    PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.

    Published: 14 May 2024
    6.1
    Medium

    CVE-2024-32733

    Last Modified: 15 Apr 2026

    Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application

    Published: 14 May 2024
    5.5
    Medium

    CVE-2024-32731

    Last Modified: 15 Apr 2026

    SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. 

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-0870

    Last Modified: 15 Apr 2026

    The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and 'save_email_settings' functions in all versions up to, and including, 4.12.0. This makes it possible for unauthenticated attackers to modify WooCommerce settings.

    Published: 14 May 2024
    4.3
    Medium

    CVE-2023-6812

    Last Modified: 8 Apr 2026

    The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

    Published: 14 May 2024
    —
    Unknown

    CVE-2024-4810

    Last Modified: 29 May 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE has been replaced by CVE-2024-36015.

    Published: 14 May 2024
    7.8
    High

    CVE-2024-4712

    Last Modified: 30 Jan 2025

    An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can lead to local privilege escalation. Note: This CVE has been split into two (CVE-2024-4712 and CVE-2024-8405) and it’s been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server.

    Published: 14 May 2024
    7.8
    High

    CVE-2024-3037

    Last Modified: 27 Jan 2025

    An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server. Important: In most installations, this risk is mitigated by the default Windows Server configuration, which typically restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log in to the local console of the Windows environment hosting the PaperCut NG/MF application server. Note: This CVE has been split into two separate CVEs (CVE-2024-3037 and CVE-2024-8404) and it’s been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard users on the host server.

    Published: 14 May 2024
    6.4
    Medium

    CVE-2024-4854

    Last Modified: 27 Mar 2026

    MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-4871

    Last Modified: 15 Apr 2026

    A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.

    Published: 14 May 2024
    4.7
    Medium

    CVE-2023-46103

    Last Modified: 15 Apr 2026

    Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.

    Published: 14 May 2024
    5.9
    Medium

    CVE-2024-4769

    Last Modified: 1 Apr 2025

    When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    Published: 14 May 2024
    3.6
    Low

    CVE-2024-4853

    Last Modified: 27 Mar 2026

    Memory handling issue in editcap could cause denial of service via crafted capture file

    Published: 14 May 2024
    3.6
    Low

    CVE-2024-4855

    Last Modified: 27 Mar 2026

    Use after free issue in editcap could cause denial of service via crafted capture file

    Published: 14 May 2024
    6.3
    Medium

    CVE-2024-30045

    Last Modified: 3 May 2025

    .NET and Visual Studio Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.5
    Medium

    CVE-2024-3044

    Last Modified: 10 Dec 2025

    Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

    Published: 14 May 2024
    7.5
    High

    CVE-2024-3372

    Last Modified: 22 Sept 2025

    Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-3374

    Last Modified: 29 Sept 2025

    An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.

    Published: 14 May 2024
    5.9
    Medium

    CVE-2024-30046

    Last Modified: 3 May 2025

    Visual Studio Denial of Service Vulnerability

    Published: 14 May 2024
    8.1
    High

    CVE-2024-32004

    Last Modified: 6 Jan 2026

    Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

    Published: 14 May 2024
    9
    Critical

    CVE-2024-32002

    Last Modified: 4 Nov 2025

    Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

    Published: 14 May 2024
    7.3
    High

    CVE-2024-32465

    Last Modified: 5 Jan 2026

    Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

    Published: 14 May 2024
    4.3
    Medium

    CVE-2024-4767

    Last Modified: 1 Apr 2025

    If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    Published: 14 May 2024
    6.1
    Medium

    CVE-2024-4768

    Last Modified: 1 Apr 2025

    A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-4770

    Last Modified: 1 Apr 2025

    When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-4777

    Last Modified: 13 Mar 2025

    Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    Published: 14 May 2024
    3.9
    Low

    CVE-2024-32021

    Last Modified: 5 Jan 2026

    Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over the filesystem may creating hardlinks to arbitrary user-owned files on the same filesystem in the target Git repository's `objects/` directory. When cloning a repository over the filesystem (without explicitly specifying the `file://` protocol or `--no-local`), the optimizations for local cloning will be used, which include attempting to hard link the object files instead of copying them. While the code includes checks against symbolic links in the source repository, which were added during the fix for CVE-2022-39253, these checks can still be raced because the hard link operation ultimately follows symlinks. If the object on the filesystem appears as a file during the check, and then a symlink during the operation, this will allow the adversary to bypass the check and create hardlinks in the destination objects directory to arbitrary, user-readable files. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.

    Published: 14 May 2024
    3.9
    Low

    CVE-2024-32020

    Last Modified: 6 Jan 2026

    Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. Cloning local repositories will cause Git to either copy or hardlink files of the source repository into the target repository. This significantly speeds up such local clones compared to doing a "proper" clone and saves both disk space and compute time. When cloning a repository located on the same disk that is owned by a different user than the current user we also end up creating such hardlinks. These files will continue to be owned and controlled by the potentially-untrusted user and can be rewritten by them at will in the future. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-4367

    Last Modified: 12 May 2026

    A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

    Published: 14 May 2024
    2.8
    Low

    CVE-2023-45733

    Last Modified: 15 Apr 2026

    Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access.

    Published: 14 May 2024
    6
    Medium

    CVE-2023-47855

    Last Modified: 31 Aug 2026

    Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 May 2024
    7.9
    High

    CVE-2023-45745

    Last Modified: 31 Aug 2026

    Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 May 2024
    5.5
    Medium

    CVE-2024-27810

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to read sensitive location information.

    Published: 13 May 2024
    5.5
    Medium

    CVE-2024-27847

    Last Modified: 2 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to bypass Privacy preferences.

    Published: 13 May 2024
    7.8
    High

    CVE-2024-27796

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An attacker may be able to elevate privileges.

    Published: 13 May 2024
    5.5
    Medium

    CVE-2024-27827

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to read arbitrary files.

    Published: 13 May 2024
    5.5
    Medium

    CVE-2024-27816

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker may be able to access user data.

    Published: 13 May 2024
    5.5
    Medium

    CVE-2024-27841

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.

    Published: 13 May 2024
    4.7
    Medium

    CVE-2024-27821

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may output sensitive user data without consent.

    Published: 13 May 2024
    3.3
    Low

    CVE-2024-27837

    Last Modified: 2 Apr 2026

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.

    Published: 13 May 2024
    5.5
    Medium

    CVE-2024-23229

    Last Modified: 2 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.5. A malicious application may be able to access Find My data.

    Published: 13 May 2024
    7.8
    High

    CVE-2024-27843

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to elevate privileges.

    Published: 13 May 2024
    7.8
    High

    CVE-2024-27818

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.

    Published: 13 May 2024
    5.5
    Medium

    CVE-2024-27789

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.7. An app may be able to access user-sensitive data.

    Published: 13 May 2024