Vulnerabilities (CVE)

Total 393688 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-49506 2026-06-17 N/A N/A
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set the encryption key for a filesystem
CVE-2024-49505 1 Opensuse 1 Mirrorcache 2026-06-17 N/A 6.1 MEDIUM
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in theĀ  REGEX and P parameters. This issue affects MirrorCache before 1.083.
CVE-2024-49504 2026-06-17 N/A N/A
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
CVE-2024-49503 2026-06-17 N/A 3.5 LOW
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
CVE-2024-49502 2026-06-17 N/A 3.5 LOW
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
CVE-2024-49501 2026-06-17 N/A 5.7 MEDIUM
Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.
CVE-2024-49422 1 Samsung 1 Android 2026-06-17 N/A 5.2 MEDIUM
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.
CVE-2024-49421 2 Google, Samsung 2 Android, Quick Share 2026-06-17 N/A 4.3 MEDIUM
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
CVE-2024-49420 2026-06-17 N/A 7.5 HIGH
Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.
CVE-2024-49419 2026-06-17 N/A 4.3 MEDIUM
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.
CVE-2024-49418 2026-06-17 N/A 6.5 MEDIUM
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.
CVE-2024-49417 1 Samsung 1 Smart Touch Call 2026-06-17 N/A 2.0 LOW
Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
CVE-2024-49416 1 Samsung 1 Smartthings 2026-06-17 N/A 4.0 MEDIUM
Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.
CVE-2024-49415 1 Samsung 1 Android 2026-06-17 N/A 8.1 HIGH
Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.
CVE-2024-49414 1 Samsung 1 Android 2026-06-17 N/A 2.4 LOW
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
CVE-2024-49413 1 Samsung 1 Android 2026-06-17 N/A 7.1 HIGH
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
CVE-2024-49412 2026-06-17 N/A 5.5 MEDIUM
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
CVE-2024-49411 1 Samsung 1 Android 2026-06-17 N/A 4.3 MEDIUM
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
CVE-2024-49410 1 Samsung 1 Android 2026-06-17 N/A 5.9 MEDIUM
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.
CVE-2024-49409 1 Samsung 2 Galaxy S24, Galaxy S24 Firmware 2026-06-17 N/A 6.4 MEDIUM
Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.