CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-22472

    Last Modified: 15 Apr 2026

    A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all versions of Silicon Labs 500 Series SDK prior to v6.85.2 running on Silicon Labs 500 series Z-wave devices.

    Published: 7 May 2024
    2.4
    Low

    CVE-2024-20855

    Last Modified: 7 Feb 2025

    Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.

    Published: 7 May 2024
    6.2
    Medium

    CVE-2024-20872

    Last Modified: 7 Jan 2026

    Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

    Published: 7 May 2024
    4.9
    Medium

    CVE-2024-20871

    Last Modified: 7 Jan 2026

    Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

    Published: 7 May 2024
    5.1
    Medium

    CVE-2024-20870

    Last Modified: 17 Jul 2025

    Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.

    Published: 7 May 2024
    5.5
    Medium

    CVE-2024-20869

    Last Modified: 17 Jul 2025

    Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.

    Published: 7 May 2024
    4.4
    Medium

    CVE-2024-20868

    Last Modified: 17 Jul 2025

    Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.

    Published: 7 May 2024
    5.5
    Medium

    CVE-2024-20867

    Last Modified: 17 Jul 2025

    Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.

    Published: 7 May 2024
    5.7
    Medium

    CVE-2024-20866

    Last Modified: 10 Feb 2025

    Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

    Published: 7 May 2024
    6.6
    Medium

    CVE-2024-20865

    Last Modified: 10 Feb 2025

    Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.

    Published: 7 May 2024
    5.5
    Medium

    CVE-2024-20864

    Last Modified: 7 Feb 2025

    Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.

    Published: 7 May 2024
    6.7
    Medium

    CVE-2024-20863

    Last Modified: 10 Feb 2025

    Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

    Published: 7 May 2024
    6
    Medium

    CVE-2024-20862

    Last Modified: 10 Feb 2025

    Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

    Published: 7 May 2024
    6
    Medium

    CVE-2024-20861

    Last Modified: 10 Feb 2025

    Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.

    Published: 7 May 2024
    4
    Medium

    CVE-2024-20860

    Last Modified: 7 Feb 2025

    Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.

    Published: 7 May 2024
    5.5
    Medium

    CVE-2024-20859

    Last Modified: 10 Feb 2025

    Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

    Published: 7 May 2024
    4
    Medium

    CVE-2024-20858

    Last Modified: 10 Feb 2025

    Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

    Published: 7 May 2024
    4
    Medium

    CVE-2024-20857

    Last Modified: 10 Feb 2025

    Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

    Published: 7 May 2024
    4.3
    Medium

    CVE-2024-20856

    Last Modified: 7 Feb 2025

    Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

    Published: 7 May 2024
    4.4
    Medium

    CVE-2024-20821

    Last Modified: 15 Apr 2026

    A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode, which disables security features. This attack needs additional privilege to control TEE.

    Published: 7 May 2024
    6.5
    Medium

    CVE-2024-34517

    Last Modified: 28 Aug 2026

    The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

    Published: 7 May 2024
    4.1
    Medium

    CVE-2024-33748

    Last Modified: 15 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.

    Published: 7 May 2024
    8.8
    High

    CVE-2024-29150

    Last Modified: 15 Apr 2026

    An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is able to create symlinks to sensitive and protected data in locations that are used for debugging files. Given that the process of gathering debug logs is carried out with root privileges, any file referenced in the symlink is consequently written to the debug archive, thereby granting accessibility to the attacker.

    Published: 7 May 2024
    6.3
    Medium

    CVE-2024-33122

    Last Modified: 1 May 2025

    Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.

    Published: 7 May 2024
    7.3
    High

    CVE-2024-33148

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

    Published: 7 May 2024
    5.3
    Medium

    CVE-2024-33858

    Last Modified: 18 Apr 2025

    An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside the /tmp directory.

    Published: 7 May 2024
    4.9
    Medium

    CVE-2024-34314

    Last Modified: 14 Mar 2025

    CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.

    Published: 7 May 2024
    4.3
    Medium

    CVE-2024-32369

    Last Modified: 17 Jun 2025

    SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-32370

    Last Modified: 17 Jun 2025

    An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.

    Published: 7 May 2024
    7.5
    High

    CVE-2024-32371

    Last Modified: 17 Jun 2025

    An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-33120

    Last Modified: 1 May 2025

    Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

    Published: 7 May 2024
    7.5
    High

    CVE-2024-33139

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

    Published: 7 May 2024
    8.8
    High

    CVE-2024-33144

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.

    Published: 7 May 2024
    9.1
    Critical

    CVE-2024-33146

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.

    Published: 7 May 2024
    8.8
    High

    CVE-2024-33147

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-33164

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2023-46012

    Last Modified: 30 Jun 2025

    Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

    Published: 7 May 2024
    9.4
    Critical

    CVE-2024-25507

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.aspx.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-25508

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.

    Published: 7 May 2024
    9.4
    Critical

    CVE-2024-25509

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file_download.aspx.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-25510

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx.

    Published: 7 May 2024
    9.4
    Critical

    CVE-2024-25511

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.

    Published: 7 May 2024
    8.1
    High

    CVE-2024-25512

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.aspx.

    Published: 7 May 2024
    7.8
    High

    CVE-2024-25513

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.

    Published: 7 May 2024
    9.4
    Critical

    CVE-2024-25514

    Last Modified: 16 Apr 2025

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx.

    Published: 7 May 2024
    7.4
    High

    CVE-2024-29149

    Last Modified: 15 Apr 2026

    An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-33124

    Last Modified: 1 May 2025

    Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..

    Published: 7 May 2024
    8.1
    High

    CVE-2024-33149

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-33153

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-33155

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.

    Published: 7 May 2024