Total
36333 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-0029 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2024-0025 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2024-0024 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |||||
| CVE-2024-0022 | 1 Google | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2024-0021 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |||||
| CVE-2024-0020 | 1 Google | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2024-0019 | 1 Google | 1 Android | 2026-06-17 | N/A | 5.0 MEDIUM |
| In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation. | |||||
| CVE-2024-0015 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2024-0014 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2024-0003 | 1 Purestorage | 1 Purity\/\/fa | 2026-06-17 | N/A | 9.1 CRITICAL |
| A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access. | |||||
| CVE-2024-0002 | 1 Purestorage | 1 Purity\/\/fa | 2026-06-17 | N/A | 10.0 CRITICAL |
| A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array. | |||||
| CVE-2023-7271 | 1 Huawei | 2 Emui, Harmonyos | 2026-06-17 | N/A | 5.5 MEDIUM |
| Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability. | |||||
| CVE-2023-7266 | 1 Huawei | 6 Tc7001-10, Tc7001-10 Firmware, Ws7200-10 and 3 more | 2026-06-17 | N/A | 7.5 HIGH |
| Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE-2023-7266 | |||||
| CVE-2023-7265 | 1 Huawei | 2 Emui, Harmonyos | 2026-06-17 | N/A | 4.0 MEDIUM |
| Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability | |||||
| CVE-2023-7261 | 1 Google | 2 Chrome, Updater | 2026-06-17 | N/A | 7.8 HIGH |
| Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High) | |||||
| CVE-2023-7252 | 1 Tickera | 1 Tickera | 2026-06-17 | N/A | 5.3 MEDIUM |
| The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets. | |||||
| CVE-2023-7248 | 1 Opentext | 1 Vertica | 2026-06-17 | N/A | 5.0 MEDIUM |
| Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the following Vertica Management Console versions: 10.x 11.1.1-24 or lower 12.0.4-18 or lower Please upgrade to one of the following Vertica Management Console versions: 10.x to upgrade to latest versions from below. 11.1.1-25 12.0.4-19 23.x 24.x | |||||
| CVE-2023-7247 | 1 Wp-buy | 1 Login As User Or Customer \(user Switching\) | 2026-06-17 | N/A | 4.9 MEDIUM |
| The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site. | |||||
| CVE-2023-7245 | 1 Openvpn | 1 Connect | 2026-06-17 | N/A | 7.8 HIGH |
| The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable | |||||
| CVE-2023-7239 | 1 Jeroensormani | 1 Wp Dashboard Notes | 2026-06-17 | N/A | 7.5 HIGH |
| The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users. | |||||
