Export limit exceeded: 74877 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (74877 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-36063 1 Goodwy Com 1 Right Dialer 2024-11-08 7.5 High
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component.
CVE-2024-9579 2 Hp, Poly 24 Poly Studio G62, Poly Studio G62 Firmware, Poly Studio G7500 and 21 more 2024-11-08 7.5 High
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
CVE-2024-49522 1 Adobe 1 Substance 3d Painter 2024-11-08 7.8 High
Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-29117 2 Enel X, Enelx 3 Juicebox Pro3.0 22kw Cellular, Waybox Pro, Waybox Pro Firmware 2024-11-08 8.8 High
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
CVE-2024-10263 1 Tickera 1 Tickera 2024-11-08 7.3 High
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVE-2024-51739 1 Combodo 1 Itop 2024-11-08 7.5 High
Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This fix is included in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. Users unable to upgrade may overload the dictionary entry `"UI:ResetPwd-Error-WrongLogin"` through an extension and replace it with a generic message.
CVE-2024-7985 2 Fileorganizer, Softaculous 2 Fileorganizer, Fileorganizer 2024-11-08 7.5 High
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: The FileOrganizer Pro plugin must be installed and active to allow Subscriber+ users to upload files.
CVE-2024-38408 1 Qualcomm 470 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 467 more 2024-11-08 8.2 High
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-22066 1 Zte 8 Zxr10 160, Zxr10 160 Firmware, Zxr10 1800-2s and 5 more 2024-11-08 7.5 High
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
CVE-2024-43966 1 Starkdigital 1 Wp Testimonial Widget 2024-11-08 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.
CVE-2024-33068 1 Qualcomm 246 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 243 more 2024-11-07 7.5 High
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-38403 1 Qualcomm 156 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 153 more 2024-11-07 7.5 High
Transient DOS while parsing BTM ML IE when per STA profile is not included.
CVE-2024-38405 1 Qualcomm 200 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 197 more 2024-11-07 7.5 High
Transient DOS while processing the CU information from RNR IE.
CVE-2024-23385 1 Qualcomm 189 205 Mobile Platform, 205 Mobile Platform Firmware, Apq8017 and 186 more 2024-11-07 7.5 High
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
CVE-2024-51523 1 Huawei 1 Harmonyos 2024-11-07 7.1 High
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-51526 1 Huawei 1 Harmonyos 2024-11-07 8.2 High
Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-38423 1 Qualcomm 416 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 413 more 2024-11-07 7.8 High
Memory corruption while processing GPU page table switch.
CVE-2024-38422 1 Qualcomm 541 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 538 more 2024-11-07 7.8 High
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38421 1 Qualcomm 157 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 7800 and 154 more 2024-11-07 7.8 High
Memory corruption while processing GPU commands.
CVE-2024-38419 1 Qualcomm 299 Ar8035, Ar8035 Firmware, Csra6620 and 296 more 2024-11-07 7.8 High
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.