CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-22369

    Last Modified: 2 Apr 2025

    Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

    Published: 19 Feb 2024
    8.8
    High

    CVE-2024-21891

    Last Modified: 30 Apr 2025

    Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

    Published: 19 Feb 2024
    10
    Critical

    CVE-2024-1597

    Last Modified: 3 Nov 2025

    pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.

    Published: 19 Feb 2024
    7.8
    High

    CVE-2022-48624

    Last Modified: 27 Mar 2025

    close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

    Published: 19 Feb 2024
    5.5
    Medium

    CVE-2020-36774

    Last Modified: 7 May 2025

    plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

    Published: 19 Feb 2024
    7.5
    High

    CVE-2022-48625

    Last Modified: 26 Aug 2025

    Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

    Published: 19 Feb 2024
    6.1
    Medium

    CVE-2024-26318

    Last Modified: 25 Mar 2025

    Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.

    Published: 19 Feb 2024
    6.5
    Medium

    CVE-2024-21890

    Last Modified: 30 Apr 2025

    The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For example: ``` --allow-fs-read=/home/node/.ssh/*.pub ``` will ignore `pub` and give access to everything after `.ssh/`. This misleading documentation affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

    Published: 19 Feb 2024
    9.8
    Critical

    CVE-2024-21896

    Last Modified: 30 Apr 2025

    The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely, Buffer.prototype.utf8Write, the application can modify the result of path.resolve(), which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

    Published: 19 Feb 2024
    9.8
    Critical

    CVE-2024-23114

    Last Modified: 2 Apr 2025

    Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

    Published: 19 Feb 2024
    9.1
    Critical

    CVE-2024-24722

    Last Modified: 2 Apr 2025

    An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.

    Published: 19 Feb 2024
    5.5
    Medium

    CVE-2024-26308

    Last Modified: 27 Mar 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

    Published: 19 Feb 2024
    5.3
    Medium

    CVE-2024-26327

    Last Modified: 7 May 2025

    An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.

    Published: 19 Feb 2024
    8.1
    High

    CVE-2024-25710

    Last Modified: 4 Nov 2025

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

    Published: 19 Feb 2024
    5.3
    Medium

    CVE-2024-1726

    Last Modified: 15 Apr 2026

    A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has knowledge of any POST, PUT, or PATCH request paths, they can potentially identify vulnerable endpoints and trigger excessive resource usage as the endpoints process the requests. This can result in a denial of service.

    Published: 19 Feb 2024
    4.4
    Medium

    CVE-2023-5779

    Last Modified: 22 Jan 2025

    can: out of bounds in remove_rx_filter function

    Published: 18 Feb 2024
    8
    High

    CVE-2023-6249

    Last Modified: 23 Jan 2025

    Signed to unsigned conversion esp32_ipm_send

    Published: 18 Feb 2024
    8
    High

    CVE-2023-6749

    Last Modified: 22 Jan 2025

    Unchecked length coming from user input in settings shell

    Published: 18 Feb 2024
    7.5
    High

    CVE-2022-48621

    Last Modified: 6 Dec 2024

    Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    9.8
    Critical

    CVE-2023-52381

    Last Modified: 13 Mar 2025

    Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

    Published: 18 Feb 2024
    4.3
    Medium

    CVE-2023-52380

    Last Modified: 13 Mar 2025

    Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52379

    Last Modified: 18 Mar 2025

    Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    9.8
    Critical

    CVE-2023-52378

    Last Modified: 29 Mar 2025

    Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 18 Feb 2024
    7.4
    High

    CVE-2023-52377

    Last Modified: 13 Mar 2025

    Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52376

    Last Modified: 13 Mar 2025

    Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52375

    Last Modified: 26 Mar 2025

    Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52374

    Last Modified: 13 Mar 2025

    Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52373

    Last Modified: 27 Mar 2025

    Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52372

    Last Modified: 13 Mar 2025

    Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affect availability.

    Published: 18 Feb 2024
    3.5
    Low

    CVE-2023-52371

    Last Modified: 12 Jul 2025

    Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.

    Published: 18 Feb 2024
    9.8
    Critical

    CVE-2023-52370

    Last Modified: 24 Apr 2025

    Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.

    Published: 18 Feb 2024
    9.1
    Critical

    CVE-2023-52369

    Last Modified: 25 Mar 2025

    Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.

    Published: 18 Feb 2024
    5.3
    Medium

    CVE-2023-52368

    Last Modified: 13 Mar 2025

    Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 18 Feb 2024
    7.7
    High

    CVE-2023-52367

    Last Modified: 13 Mar 2025

    Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52366

    Last Modified: 13 Mar 2025

    Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 18 Feb 2024
    5.3
    Medium

    CVE-2023-52365

    Last Modified: 13 Mar 2025

    Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 18 Feb 2024
    5.3
    Medium

    CVE-2023-52363

    Last Modified: 27 Mar 2025

    Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52362

    Last Modified: 13 Mar 2025

    Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52361

    Last Modified: 9 Dec 2024

    The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52360

    Last Modified: 17 Mar 2025

    Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.

    Published: 18 Feb 2024
    6.2
    Medium

    CVE-2023-52358

    Last Modified: 13 Mar 2025

    Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52357

    Last Modified: 6 Dec 2024

    Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52097

    Last Modified: 13 Mar 2025

    Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    7.5
    High

    CVE-2023-52387

    Last Modified: 27 Mar 2025

    Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 18 Feb 2024
    0
    Low

    CVE-2024-26464

    Last Modified: 28 Feb 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 18 Feb 2024
    7.1
    High

    CVE-2022-41737

    Last Modified: 31 Dec 2024

    IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.

    Published: 17 Feb 2024
    7.5
    High

    CVE-2022-41738

    Last Modified: 31 Dec 2024

    IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.

    Published: 17 Feb 2024
    2.2
    Low

    CVE-2022-42443

    Last Modified: 22 Jan 2025

    An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.

    Published: 17 Feb 2024
    4
    Medium

    CVE-2023-50951

    Last Modified: 3 Dec 2024

    IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.

    Published: 17 Feb 2024
    5.1
    Medium

    CVE-2024-22337

    Last Modified: 3 Dec 2024

    IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.

    Published: 17 Feb 2024