CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2021-20450

    Last Modified: 18 Jun 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 196640.

    Published: 3 May 2024
    5.9
    Medium

    CVE-2020-4874

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837.

    Published: 3 May 2024
    8.8
    High

    CVE-2023-37407

    Last Modified: 7 Jan 2025

    IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 260116.

    Published: 3 May 2024
    2.8
    Low

    CVE-2024-3480

    Last Modified: 15 Apr 2026

    An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.

    Published: 3 May 2024
    2.8
    Low

    CVE-2024-3479

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.

    Published: 3 May 2024
    6.3
    Medium

    CVE-2024-3109

    Last Modified: 15 Apr 2026

    A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.

    Published: 3 May 2024
    5.5
    Medium

    CVE-2024-3108

    Last Modified: 15 Apr 2026

    An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. 

    Published: 3 May 2024
    6.5
    Medium

    CVE-2023-41830

    Last Modified: 15 Apr 2026

    An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. 

    Published: 3 May 2024
    4.4
    Medium

    CVE-2023-41828

    Last Modified: 15 Apr 2026

    An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.  

    Published: 3 May 2024
    5.1
    Medium

    CVE-2023-41826

    Last Modified: 15 Apr 2026

    A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. 

    Published: 3 May 2024
    2.8
    Low

    CVE-2023-41825

    Last Modified: 15 Apr 2026

    A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. 

    Published: 3 May 2024
    2.8
    Low

    CVE-2023-41824

    Last Modified: 15 Apr 2026

    An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.

    Published: 3 May 2024
    4.4
    Medium

    CVE-2023-41823

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. 

    Published: 3 May 2024
    4.8
    Medium

    CVE-2023-41822

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. 

    Published: 3 May 2024
    5
    Medium

    CVE-2023-41821

    Last Modified: 15 Apr 2026

    A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. 

    Published: 3 May 2024
    5
    Medium

    CVE-2023-41820

    Last Modified: 15 Apr 2026

    An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices. 

    Published: 3 May 2024
    6.1
    Medium

    CVE-2023-41819

    Last Modified: 15 Apr 2026

    A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. 

    Published: 3 May 2024
    5
    Medium

    CVE-2023-41818

    Last Modified: 15 Apr 2026

    An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. 

    Published: 3 May 2024
    2.8
    Low

    CVE-2023-41817

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.

    Published: 3 May 2024
    5
    Medium

    CVE-2023-41816

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. 

    Published: 3 May 2024
    5.1
    Medium

    CVE-2023-6363

    Last Modified: 27 Mar 2025

    Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

    Published: 3 May 2024
    9.8
    Critical

    CVE-2024-4466

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to send a specially crafted SQL query to the pass parameter and retrieve all the data stored in the database.

    Published: 3 May 2024
    7.8
    High

    CVE-2024-4461

    Last Modified: 15 Apr 2026

    Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary code into the unquoted service path, resulting in privilege escalation.

    Published: 3 May 2024
    7.8
    High

    CVE-2024-34072

    Last Modified: 15 Apr 2026

    sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted data is passed as pickled object arrays. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity. Users are advised to upgrade to version 2.218.0. Users unable to upgrade should not pass pickled numpy object arrays which originated from an untrusted source, or that could have been tampered with. Only pass pickled numpy object arrays from trusted sources.

    Published: 3 May 2024
    7.8
    High

    CVE-2024-34073

    Last Modified: 15 Apr 2026

    sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for potentially unsafe Operating System (OS) Command Injection if inappropriate command is passed as the “requirements_path” parameter. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity. This issue has been addressed in version 2.214.3. Users are advised to upgrade. Users unable to upgrade should not override the “requirements_path” parameter of capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils`, and instead use the default value.

    Published: 3 May 2024
    9.6
    Critical

    CVE-2024-32986

    Last Modified: 15 Apr 2026

    PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines into XDG Desktop Entries (on Linux) and `AppInfo.ini` (on PortableApps.com). This allowed malicious web apps to introduce keys like `Exec`, which could run arbitrary code when the affected web app was launched. This vulnerability affects all Linux and PortableApps.com users of all PWAsForFirefox versions up to (excluding) 2.12.0. Windows and macOS users are not affected. This vulnerability has been fixed in commit `9932d4b` which has been included in release in v2.12.0. The main fix is implemented in the native part, but the extension also contains additional fixes. All Linux and PortableApps.com users are advised to update to this version as soon as possible. It is also recommended for Windows and macOS users to update to this version, as it contains additional fixes related to properties sanitization. There are no known workarounds for this vulnerability.

    Published: 3 May 2024
    2.5
    Low

    CVE-2024-34063

    Last Modified: 15 Apr 2026

    vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes in third-party cryptographic dependencies (the Dalek crates), which moved secret zeroization capabilities behind a feature flag and defaulted this feature to off. The degraded zeroization capabilities could result in the production of more memory copies of encryption secrets and secrets could linger in memory longer than necessary. This marginally increases the risk of sensitive data exposure. This issue has been addressed in version 0.6.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 3 May 2024
    7.4
    High

    CVE-2024-1067

    Last Modified: 28 Mar 2025

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. On Armv8.0 cores, there are certain combinations of the Linux Kernel and Mali GPU kernel driver configurations that would allow the GPU operations to affect the userspace memory of other processes. This issue affects Bifrost GPU Kernel Driver: from r41p0 through r47p0; Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

    Published: 3 May 2024
    6.7
    Medium

    CVE-2024-1395

    Last Modified: 27 Mar 2025

    Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. This issue affects Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2024-33914

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2024-33915

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.

    Published: 3 May 2024
    6.5
    Medium

    CVE-2024-33919

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2024-33920

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2024-33921

    Last Modified: 28 Apr 2026

    Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

    Published: 3 May 2024
    6.3
    Medium

    CVE-2024-33923

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2024-33925

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2024-33929

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

    Published: 3 May 2024
    6.5
    Medium

    CVE-2024-33931

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2024-33937

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.

    Published: 3 May 2024
    5.7
    Medium

    CVE-2024-23914

    Last Modified: 15 Apr 2026

    Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.

    Published: 3 May 2024
    4
    Medium

    CVE-2024-23913

    Last Modified: 15 Apr 2026

    Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation.

    Published: 3 May 2024
    4
    Medium

    CVE-2024-23912

    Last Modified: 15 Apr 2026

    Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation.

    Published: 3 May 2024
    6.6
    Medium

    CVE-2023-35701

    Last Modified: 10 Jul 2025

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is running. The malicious user must have sufficient permissions to specify/edit JDBC URL(s) in an endpoint relying on the Hive JDBC driver and the JDBC client process must run under a privileged user to fully exploit the vulnerability.  The attacker can setup a malicious HTTP server and specify a JDBC URL pointing towards this server. When a JDBC connection is attempted, the malicious HTTP server can provide a special response with customized payload that can trigger the execution of certain commands in the JDBC client.This issue affects Apache Hive: from 4.0.0-alpha-1 before 4.0.0. Users are recommended to upgrade to version 4.0.0, which fixes the issue.

    Published: 3 May 2024
    5.7
    Medium

    CVE-2024-28072

    Last Modified: 25 Feb 2025

    A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2024-24710

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.

    Published: 3 May 2024
    7.6
    High

    CVE-2024-32810

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2023-25457

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slider: from n/a through 1.5.1.

    Published: 3 May 2024
    4.3
    Medium

    CVE-2023-44472

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.28.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2024-33941

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.

    Published: 3 May 2024
    5.9
    Medium

    CVE-2024-32831

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lorna Timbah (webgrrrl) Accessibility Widget allows Stored XSS.This issue affects Accessibility Widget: from n/a through 2.2.

    Published: 3 May 2024