CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2023-40105

    Last Modified: 13 Dec 2024

    In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.5
    High

    CVE-2023-40104

    Last Modified: 16 Dec 2024

    In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2023-40100

    Last Modified: 16 Dec 2024

    In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.3
    High

    CVE-2024-25123

    Last Modified: 9 Jan 2025

    MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable to path manipulation attack. By modifying file paths, an attacker can acquire sensitive information from different resources. The `filename` variable is joined with other variables to form a file path in `_file`. However, `filename` is a route parameter that can capture path type values i.e. values including slashes (\). So it is possible for an attacker to manipulate the file being read by assigning a value containing ../ to `filename` and so the attacker may be able to gain access to other files on the host filesystem. This issue has been addressed in MSS version 8.3.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 15 Feb 2024
    7.5
    High

    CVE-2023-6123

    Last Modified: 4 Aug 2026

    Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

    Published: 15 Feb 2024
    9
    Critical

    CVE-2023-40057

    Last Modified: 21 Nov 2024

    The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

    Published: 15 Feb 2024
    7.9
    High

    CVE-2024-23477

    Last Modified: 21 Nov 2024

    The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

    Published: 15 Feb 2024
    9.6
    Critical

    CVE-2024-23476

    Last Modified: 21 Nov 2024

    The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution.

    Published: 15 Feb 2024
    8
    High

    CVE-2024-23478

    Last Modified: 21 Nov 2024

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution.

    Published: 15 Feb 2024
    9.6
    Critical

    CVE-2024-23479

    Last Modified: 21 Nov 2024

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

    Published: 15 Feb 2024
    6.1
    Medium

    CVE-2024-21728

    Last Modified: 4 Jun 2025

    An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a base64 malicious URL.

    Published: 15 Feb 2024
    7
    High

    CVE-2024-0041

    Last Modified: 28 Mar 2025

    In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.5
    High

    CVE-2024-0040

    Last Modified: 16 Dec 2024

    In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0038

    Last Modified: 16 Dec 2024

    In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    3.3
    Low

    CVE-2024-0037

    Last Modified: 3 Dec 2024

    In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0036

    Last Modified: 16 Dec 2024

    In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0035

    Last Modified: 16 Dec 2024

    In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0034

    Last Modified: 19 Mar 2025

    In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0033

    Last Modified: 16 Dec 2024

    In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    6.5
    Medium

    CVE-2024-0032

    Last Modified: 26 Aug 2025

    In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2024-0031

    Last Modified: 16 Dec 2024

    In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    5.5
    Medium

    CVE-2024-0030

    Last Modified: 16 Dec 2024

    In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0029

    Last Modified: 14 Mar 2025

    In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-0014

    Last Modified: 28 Mar 2025

    In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 15 Feb 2024
    5.3
    Medium

    CVE-2023-6937

    Last Modified: 24 Apr 2025

    wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS messages using different keys into one (D)TLS record. The most extreme edge case is that, in (D)TLS 1.3, it was possible that an unencrypted (D)TLS 1.3 record from the server containing first a ServerHello message and then the rest of the first server flight would be accepted by a wolfSSL client. In (D)TLS 1.3 the handshake is encrypted after the ServerHello but a wolfSSL client would accept an unencrypted flight from the server. This does not compromise key negotiation and authentication so it is assigned a low severity rating.

    Published: 15 Feb 2024
    8.8
    High

    CVE-2024-0622

    Last Modified: 23 Jan 2025

    Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation. 

    Published: 15 Feb 2024
    6.5
    Medium

    CVE-2024-0240

    Last Modified: 5 Feb 2025

    A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.

    Published: 15 Feb 2024
    7.5
    High

    CVE-2023-6255

    Last Modified: 20 May 2026

    Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable. This issue affects SoliPay Mobile App: before 5.0.8.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2023-5155

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection. This issue affects SoliPay Mobile App: before 5.0.8.

    Published: 15 Feb 2024
    7.5
    High

    CVE-2023-4993

    Last Modified: 20 May 2026

    Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data as Provided by Users. This issue affects SoliPay Mobile App: before 5.0.8.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2023-7081

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online Payment System allows SQL Injection. This issue affects Online Payment System: before 14.02.2024.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2024-23113

    Last Modified: 24 Oct 2025

    A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

    Published: 15 Feb 2024
    4.8
    Medium

    CVE-2023-47537

    Last Modified: 14 Jan 2026

    An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4 all versions allows a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the FortiLink communication channel between the FortiOS device and FortiSwitch.

    Published: 15 Feb 2024
    5
    Medium

    CVE-2023-44253

    Last Modified: 13 Feb 2025

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS requests.

    Published: 15 Feb 2024
    8.8
    High

    CVE-2023-45581

    Last Modified: 21 Nov 2024

    An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.

    Published: 15 Feb 2024
    6.8
    Medium

    CVE-2023-26206

    Last Modified: 21 Nov 2024

    An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.

    Published: 15 Feb 2024
    4.9
    Medium

    CVE-2024-20716

    Last Modified: 21 Nov 2024

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue does not require user interaction.

    Published: 15 Feb 2024
    5.4
    Medium

    CVE-2024-20717

    Last Modified: 21 Nov 2024

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 15 Feb 2024
    4.3
    Medium

    CVE-2024-20718

    Last Modified: 21 Nov 2024

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into performing actions they did not intend to do, which could be used to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction, typically in the form of the victim clicking a link or visiting a malicious website.

    Published: 15 Feb 2024
    9.1
    Critical

    CVE-2024-20719

    Last Modified: 21 Nov 2024

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.

    Published: 15 Feb 2024
    9.1
    Critical

    CVE-2024-20720

    Last Modified: 16 Dec 2025

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2023-39245

    Last Modified: 23 Jan 2025

    DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.

    Published: 15 Feb 2024
    7.3
    High

    CVE-2023-39244

    Last Modified: 23 Jan 2025

    DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2023-32484

    Last Modified: 23 Jan 2025

    Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level. This is a Critical vulnerability affecting certain protocols, Dell recommends customers to upgrade at the earliest opportunity.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2023-32462

    Last Modified: 24 Apr 2025

    Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 15 Feb 2024
    9.1
    Critical

    CVE-2023-28078

    Last Modified: 23 Jan 2025

    Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-20750

    Last Modified: 6 Dec 2024

    Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-20739

    Last Modified: 6 Dec 2024

    Audition versions 24.0.3, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Feb 2024
    9.8
    Critical

    CVE-2024-20738

    Last Modified: 21 Nov 2024

    Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction.

    Published: 15 Feb 2024
    7.8
    High

    CVE-2024-20726

    Last Modified: 21 Nov 2024

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Feb 2024