Total
396587 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-34688 | 1 Sap | 1 Netweaver Application Server Java | 2026-06-17 | N/A | 7.5 HIGH |
| Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application. | |||||
| CVE-2024-34687 | 1 Sap | 1 Sap Basis | 2026-06-17 | N/A | 6.5 MEDIUM |
| SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system. | |||||
| CVE-2024-34686 | 1 Sap | 1 Customer Relationship Management Webclient Ui | 2026-06-17 | N/A | 6.1 MEDIUM |
| Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application. | |||||
| CVE-2024-34685 | 1 Sap | 1 Netweaver Knowledge Management And Collaboration \(kmc-cm\) | 2026-06-17 | N/A | 6.1 MEDIUM |
| Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its confidentiality and integrity. | |||||
| CVE-2024-34684 | 1 Sap | 1 Businessobjects Business Intelligence Platform | 2026-06-17 | N/A | 3.7 LOW |
| On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files. | |||||
| CVE-2024-34683 | 1 Sap | 1 Document Builder | 2026-06-17 | N/A | 6.5 MEDIUM |
| An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser. | |||||
| CVE-2024-34682 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 2.4 LOW |
| Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode. | |||||
| CVE-2024-34681 | 2026-06-17 | N/A | 6.6 MEDIUM | ||
| Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch. | |||||
| CVE-2024-34680 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.0 MEDIUM |
| Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information. | |||||
| CVE-2024-34679 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.0 MEDIUM |
| Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege. | |||||
| CVE-2024-34678 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.9 MEDIUM |
| Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. | |||||
| CVE-2024-34677 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.0 MEDIUM |
| Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate. | |||||
| CVE-2024-34676 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.4 MEDIUM |
| Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability. | |||||
| CVE-2024-34675 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 2.4 LOW |
| Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen. | |||||
| CVE-2024-34674 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles. | |||||
| CVE-2024-34673 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.1 MEDIUM |
| Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service. | |||||
| CVE-2024-34672 | 1 Samsung | 2 Android, Video Player | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows local attackers to access video file of other users. | |||||
| CVE-2024-34671 | 1 Samsung | 1 Internet | 2026-06-17 | N/A | 3.3 LOW |
| Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | |||||
| CVE-2024-34670 | 1 Samsung | 1 Sound Assistant | 2026-06-17 | N/A | 4.0 MEDIUM |
| Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information. | |||||
| CVE-2024-34669 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.5 HIGH |
| Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability. | |||||
