Vulnerabilities (CVE)

Total 270770 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-9469 2024-11-20 N/A 8.4 HIGH
In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local escalation of privilege in a privileged app with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2018-9468 2024-11-20 N/A 7.7 HIGH
In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-33023 1 Qualcomm 314 Ar8035, Ar8035 Firmware, Csra6620 and 311 more 2024-11-20 N/A 7.8 HIGH
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
CVE-2024-33022 1 Qualcomm 248 Ar8035, Ar8035 Firmware, Csra6620 and 245 more 2024-11-20 N/A 7.8 HIGH
Memory corruption while allocating memory in HGSL driver.
CVE-2024-33021 1 Qualcomm 276 Ar8035, Ar8035 Firmware, Csra6620 and 273 more 2024-11-20 N/A 7.8 HIGH
Memory corruption while processing IOCTL call to set metainfo.
CVE-2024-33020 1 Qualcomm 196 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 193 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while processing TID-to-link mapping IE elements.
CVE-2024-33019 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more 2024-11-20 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-24051 1 Monoprice 2 Select Mini 3d Printer V2, Select Mini 3d Printer V2 Firmware 2024-11-20 N/A 5.5 MEDIUM
Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.
CVE-2024-45511 2024-11-20 N/A N/A
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.
CVE-2024-33439 2024-11-20 N/A N/A
An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.
CVE-2024-52759 1 Dlink 2 Di-8003, Di-8003 Firmware 2024-11-20 N/A 9.8 CRITICAL
D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.
CVE-2024-4705 1 Axelerant 1 Testimonials Widget 2024-11-20 N/A 5.4 MEDIUM
The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-3644 2024-11-20 N/A 4.8 MEDIUM
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-3629 2024-11-20 N/A 2.4 LOW
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-3471 2024-11-20 N/A 3.4 LOW
The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack
CVE-2024-3281 2024-11-20 N/A 8.8 HIGH
A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.
CVE-2024-3076 2024-11-20 N/A 3.8 LOW
The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVE-2024-3048 2024-11-20 N/A 5.5 MEDIUM
The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators
CVE-2024-35283 2024-11-20 N/A 6.1 MEDIUM
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.
CVE-2024-2759 2024-11-20 N/A 7.5 HIGH
Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin for PrestaShop from v1 through v4.