CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-21987

    Last Modified: 16 Dec 2024

    SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system logging configuration settings

    Published: 16 Feb 2024
    7.6
    High

    CVE-2024-25628

    Last Modified: 18 Dec 2024

    Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Feb 2024
    5.5
    Medium

    CVE-2023-40085

    Last Modified: 16 Dec 2024

    In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2023-21165

    Last Modified: 16 Dec 2024

    In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    9
    Critical

    CVE-2024-21915

    Last Modified: 11 Dec 2024

    A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.

    Published: 16 Feb 2024
    2
    Low

    CVE-2024-23591

    Last Modified: 23 Jul 2025

    ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting. The server’s NIST SP 800-193-compliant Platform Firmware Resiliency (PFR) security subsystem significantly mitigates this issue.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2024-0023

    Last Modified: 16 Dec 2024

    In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2024-0021

    Last Modified: 16 Dec 2024

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 16 Feb 2024
    5.5
    Medium

    CVE-2024-0020

    Last Modified: 19 Mar 2025

    In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    5
    Medium

    CVE-2024-0019

    Last Modified: 13 Mar 2025

    In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2024-0018

    Last Modified: 16 Dec 2024

    In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    5.5
    Medium

    CVE-2024-0017

    Last Modified: 16 Dec 2024

    In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 16 Feb 2024
    5.3
    Medium

    CVE-2024-0016

    Last Modified: 16 Dec 2024

    In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    3.3
    Low

    CVE-2024-1591

    Last Modified: 7 Feb 2025

    Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.

    Published: 16 Feb 2024
    8.3
    High

    CVE-2024-21775

    Last Modified: 26 Nov 2024

    Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2024-0015

    Last Modified: 14 Mar 2025

    In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    —
    Unknown

    CVE-2024-26287

    Last Modified: 22 Feb 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Feb 2024
    7.2
    High

    CVE-2024-22426

    Last Modified: 23 Jan 2025

    Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete system compromise.

    Published: 16 Feb 2024
    6.5
    Medium

    CVE-2024-22425

    Last Modified: 23 Jan 2025

    Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to brute-force the password of valid users in an automated manner.

    Published: 16 Feb 2024
    8.6
    High

    CVE-2023-6451

    Last Modified: 9 Jan 2025

    Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.

    Published: 16 Feb 2024
    3.3
    Low

    CVE-2023-40122

    Last Modified: 26 Nov 2024

    In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    5.5
    Medium

    CVE-2023-40093

    Last Modified: 3 Dec 2024

    In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Feb 2024
    9.8
    Critical

    CVE-2024-25414

    Last Modified: 14 Mar 2025

    An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.

    Published: 16 Feb 2024
    6.1
    Medium

    CVE-2024-22854

    Last Modified: 11 Jul 2025

    DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form.

    Published: 16 Feb 2024
    7.2
    High

    CVE-2024-25415

    Last Modified: 13 Jan 2025

    A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.

    Published: 16 Feb 2024
    6.5
    Medium

    CVE-2023-52160

    Last Modified: 4 Nov 2025

    The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.

    Published: 16 Feb 2024
    7.4
    High

    CVE-2023-46809

    Last Modified: 15 Apr 2026

    Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

    Published: 16 Feb 2024
    3.9
    Low

    CVE-2024-24758

    Last Modified: 13 Feb 2025

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Feb 2024
    7.2
    High

    CVE-2024-25413

    Last Modified: 26 Mar 2025

    A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

    Published: 16 Feb 2024
    6.5
    Medium

    CVE-2023-45860

    Last Modified: 27 Mar 2025

    In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

    Published: 16 Feb 2024
    6.5
    Medium

    CVE-2023-49508

    Last Modified: 27 Mar 2025

    Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.

    Published: 16 Feb 2024
    7.5
    High

    CVE-2023-51931

    Last Modified: 13 Jan 2025

    An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2024-21892

    Last Modified: 30 Apr 2025

    On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this exception, Node.js incorrectly applies this exception even when certain other capabilities have been set. This allows unprivileged users to inject code that inherits the process's elevated privileges.

    Published: 16 Feb 2024
    9.8
    Critical

    CVE-2024-23807

    Last Modified: 22 Jan 2026

    The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

    Published: 16 Feb 2024
    9.8
    Critical

    CVE-2024-24377

    Last Modified: 13 Jan 2025

    An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.

    Published: 16 Feb 2024
    6.5
    Medium

    CVE-2024-24750

    Last Modified: 13 Feb 2025

    Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

    Published: 16 Feb 2024
    6.3
    Medium

    CVE-2024-25083

    Last Modified: 27 Mar 2025

    An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with elevated privileges.

    Published: 16 Feb 2024
    9.8
    Critical

    CVE-2024-25320

    Last Modified: 19 Mar 2025

    Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.

    Published: 16 Feb 2024
    7.8
    High

    CVE-2024-25466

    Last Modified: 27 Mar 2025

    Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.

    Published: 16 Feb 2024
    7.5
    High

    CVE-2024-22019

    Last Modified: 4 Nov 2025

    A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

    Published: 16 Feb 2024
    5.5
    Medium

    CVE-2023-40124

    Last Modified: 13 Dec 2024

    In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40115

    Last Modified: 13 Dec 2024

    In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40114

    Last Modified: 13 Dec 2024

    In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 15 Feb 2024
    5.5
    Medium

    CVE-2023-40113

    Last Modified: 13 Dec 2024

    In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    5.5
    Medium

    CVE-2023-40112

    Last Modified: 13 Dec 2024

    In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40111

    Last Modified: 29 Mar 2025

    In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40110

    Last Modified: 19 Mar 2025

    In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40109

    Last Modified: 16 Dec 2024

    In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40107

    Last Modified: 13 Dec 2024

    In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40106

    Last Modified: 13 Dec 2024

    In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024