CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2024-25991

    Last Modified: 3 Apr 2025

    In acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    6.4
    Medium

    CVE-2024-25990

    Last Modified: 16 Apr 2025

    In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    5.9
    Medium

    CVE-2024-25989

    Last Modified: 3 Apr 2025

    In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    8.4
    High

    CVE-2024-25988

    Last Modified: 3 Apr 2025

    In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    6.7
    Medium

    CVE-2024-25987

    Last Modified: 3 Apr 2025

    In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-25986

    Last Modified: 3 Apr 2025

    In ppmp_unprotect_buf of drm_fw.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    8.4
    High

    CVE-2024-25985

    Last Modified: 3 Apr 2025

    In bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    6.2
    Medium

    CVE-2024-25984

    Last Modified: 3 Apr 2025

    In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.5
    High

    CVE-2024-22011

    Last Modified: 26 Mar 2025

    In ss_ProcessRejectComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    5.5
    Medium

    CVE-2024-22010

    Last Modified: 3 Apr 2025

    In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.1
    High

    CVE-2024-22009

    Last Modified: 3 Apr 2025

    In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-22008

    Last Modified: 16 Apr 2025

    In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    6.2
    Medium

    CVE-2024-22007

    Last Modified: 3 Apr 2025

    In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    5.3
    Medium

    CVE-2024-22006

    Last Modified: 3 Apr 2025

    OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.

    Published: 11 Mar 2024
    8.4
    High

    CVE-2024-22005

    Last Modified: 3 Apr 2025

    there is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    4.9
    Medium

    CVE-2023-7247

    Last Modified: 1 May 2025

    The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.

    Published: 11 Mar 2024
    5.3
    Medium

    CVE-2023-6444

    Last Modified: 1 May 2025

    The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.

    Published: 11 Mar 2024
    8.8
    High

    CVE-2024-23717

    Last Modified: 16 Dec 2024

    In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-23612

    Last Modified: 21 Nov 2024

    An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-23609

    Last Modified: 16 Apr 2025

    An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-23611

    Last Modified: 27 Feb 2025

    An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-23610

    Last Modified: 27 Feb 2025

    An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-23608

    Last Modified: 12 Jul 2025

    An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 11 Mar 2024
    5.4
    Medium

    CVE-2024-1487

    Last Modified: 1 Apr 2025

    The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.

    Published: 11 Mar 2024
    5.4
    Medium

    CVE-2024-0561

    Last Modified: 1 May 2025

    The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Mar 2024
    4.3
    Medium

    CVE-2024-1279

    Last Modified: 28 Mar 2025

    The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

    Published: 11 Mar 2024
    6.5
    Medium

    CVE-2024-1290

    Last Modified: 9 May 2025

    The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.

    Published: 11 Mar 2024
    7.2
    High

    CVE-2024-1068

    Last Modified: 1 May 2025

    The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.

    Published: 11 Mar 2024
    6.1
    Medium

    CVE-2024-1273

    Last Modified: 1 May 2025

    The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

    Published: 11 Mar 2024
    6.5
    Medium

    CVE-2024-0559

    Last Modified: 1 Apr 2025

    The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 11 Mar 2024
    —
    Unknown

    CVE-2024-2370

    Last Modified: 20 Mar 2024

    DO NOT USE THIS CVE ID NUMBER. Consult IDs: CVE-2018-5341. Reason: This CVE Record is a duplicate of CVE-2018-5341. Notes: All CVE users should reference CVE-2018-5341 instead of this record.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-1696

    Last Modified: 18 Feb 2025

    In Santesoft Sante FFT Imaging versions 1.4.1 and prior once a user opens a malicious DCM file on affected FFT Imaging installations, a local attacker could perform an out-of-bounds write, which could allow for arbitrary code execution.

    Published: 11 Mar 2024
    3.3
    Low

    CVE-2024-0053

    Last Modified: 27 Mar 2025

    In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    3.3
    Low

    CVE-2024-0052

    Last Modified: 13 Mar 2025

    In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-0051

    Last Modified: 16 Dec 2024

    In onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-0050

    Last Modified: 16 Dec 2024

    In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could lead to a local non-security issue with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-0049

    Last Modified: 16 Apr 2025

    In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-0048

    Last Modified: 16 Dec 2024

    In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    5.5
    Medium

    CVE-2024-0047

    Last Modified: 27 Mar 2025

    In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    7.8
    High

    CVE-2024-0046

    Last Modified: 16 Dec 2024

    In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    6.5
    Medium

    CVE-2024-0045

    Last Modified: 17 Dec 2024

    In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    6.7
    Medium

    CVE-2024-0044

    Last Modified: 28 Jan 2025

    In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    9.8
    Critical

    CVE-2024-0039

    Last Modified: 13 Mar 2025

    In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 11 Mar 2024
    8.8
    High

    CVE-2024-0670

    Last Modified: 13 Feb 2025

    Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

    Published: 11 Mar 2024
    9.8
    Critical

    CVE-2024-2184

    Last Modified: 15 Apr 2026

    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C Series/Satera MF640C Series/Satera LBP660C Series/Satera LBP620C Series firmware v12.07 and earlier, and Satera MF750C Series/Satera LBP670C Series firmware v03.09 and earlier sold in Japan.Color imageCLASS MF740C Series/Color imageCLASS MF640C Series/Color imageCLASS X MF1127C/Color imageCLASS LBP664Cdw/Color imageCLASS LBP622Cdw/Color imageCLASS X LBP1127C firmware v12.07 and earlier, and Color imageCLASS MF750C Series/Color imageCLASS X MF1333C/Color imageCLASS LBP674Cdw/Color imageCLASS X LBP1333C firmware v03.09 and earlier sold in US.i-SENSYS MF740C Series/i-SENSYS MF640C Series/C1127i Series/i-SENSYS LBP660C Series/i-SENSYS LBP620C Series/C1127P firmware v12.07 and earlier, and i-SENSYS MF750C Series/C1333i Series/i-SENSYS LBP673Cdw/C1333P firmware v03.09 and earlier sold in Europe.

    Published: 11 Mar 2024
    6.1
    Medium

    CVE-2024-28823

    Last Modified: 15 Apr 2026

    Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html.

    Published: 11 Mar 2024
    7.1
    High

    CVE-2024-28816

    Last Modified: 15 Apr 2026

    Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.

    Published: 11 Mar 2024
    6.5
    Medium

    CVE-2024-2357

    Last Modified: 15 Apr 2026

    The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.

    Published: 11 Mar 2024
    7.5
    High

    CVE-2022-46070

    Last Modified: 18 Sept 2025

    GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.

    Published: 11 Mar 2024
    6.1
    Medium

    CVE-2024-25854

    Last Modified: 22 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting a support ticket.

    Published: 11 Mar 2024