Vulnerabilities (CVE)

Total 396869 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33672 1 Veritas 1 Netbackup 2026-06-17 N/A 7.7 HIGH
An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.
CVE-2024-33671 1 Veritas 1 Backup Exec 2026-06-17 N/A 7.7 HIGH
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.
CVE-2024-33670 1 Passbolt 1 Passbolt Api 2026-06-17 N/A 4.3 MEDIUM
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
CVE-2024-33669 1 Passbolt 1 Passbolt Browser Extension 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.
CVE-2024-33667 1 Zammad 1 Zammad 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.
CVE-2024-33666 1 Zammad 1 Zammad 2026-06-17 N/A 8.6 HIGH
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
CVE-2024-33665 2026-06-17 N/A 6.1 MEDIUM
angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.
CVE-2024-33664 1 Python-jose Project 1 Python-jose 2026-06-17 N/A 5.3 MEDIUM
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
CVE-2024-33663 1 Python-jose Project 1 Python-jose 2026-06-17 N/A 6.5 MEDIUM
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
CVE-2024-33662 1 Portainer 1 Portainer 2026-06-17 N/A 7.5 HIGH
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-33661 1 Portainer 1 Portainer 2026-06-17 N/A 9.1 CRITICAL
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CVE-2024-33660 1 Ami 1 Aptio V 2026-06-17 N/A 4.3 MEDIUM
An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.
CVE-2024-33659 1 Ami 1 Aptio V 2026-06-17 N/A 8.8 HIGH
AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability.
CVE-2024-33658 1 Ami 1 Aptio V 2026-06-17 N/A 7.8 HIGH
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of this vulnerability may lead to privilege escalation and potentially arbitrary code execution, and impact Integrity.
CVE-2024-33657 1 Ami 1 Aptio V 2026-06-17 N/A 7.8 HIGH
This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks.
CVE-2024-33656 1 Ami 1 Aptio V 2026-06-17 N/A 7.8 HIGH
The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS security mechanisms
CVE-2024-33655 2026-06-17 N/A 7.5 HIGH
The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.
CVE-2024-33654 1 Siemens 1 Simcenter Femap 2026-06-17 N/A 7.8 HIGH
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
CVE-2024-33653 1 Siemens 1 Simcenter Femap 2026-06-17 N/A 7.8 HIGH
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
CVE-2024-33652 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.