Total
396869 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-33672 | 1 Veritas | 1 Netbackup | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files. | |||||
| CVE-2024-33671 | 1 Veritas | 1 Backup Exec | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files. | |||||
| CVE-2024-33670 | 1 Passbolt | 1 Passbolt Api | 2026-06-17 | N/A | 4.3 MEDIUM |
| Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page. | |||||
| CVE-2024-33669 | 1 Passbolt | 1 Passbolt Browser Extension | 2026-06-17 | N/A | 6.1 MEDIUM |
| An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user. | |||||
| CVE-2024-33667 | 1 Zammad | 1 Zammad | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist. | |||||
| CVE-2024-33666 | 1 Zammad | 1 Zammad | 2026-06-17 | N/A | 8.6 HIGH |
| An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents. | |||||
| CVE-2024-33665 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks. | |||||
| CVE-2024-33664 | 1 Python-jose Project | 1 Python-jose | 2026-06-17 | N/A | 5.3 MEDIUM |
| python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319. | |||||
| CVE-2024-33663 | 1 Python-jose Project | 1 Python-jose | 2026-06-17 | N/A | 6.5 MEDIUM |
| python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. | |||||
| CVE-2024-33662 | 1 Portainer | 1 Portainer | 2026-06-17 | N/A | 7.5 HIGH |
| Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. | |||||
| CVE-2024-33661 | 1 Portainer | 1 Portainer | 2026-06-17 | N/A | 9.1 CRITICAL |
| Portainer before 2.20.0 allows redirects when the target is not index.yaml. | |||||
| CVE-2024-33660 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 4.3 MEDIUM |
| An exploit is possible where an actor with physical access can manipulate SPI flash without being detected. | |||||
| CVE-2024-33659 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 8.8 HIGH |
| AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability. | |||||
| CVE-2024-33658 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 7.8 HIGH |
| APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of this vulnerability may lead to privilege escalation and potentially arbitrary code execution, and impact Integrity. | |||||
| CVE-2024-33657 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 7.8 HIGH |
| This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks. | |||||
| CVE-2024-33656 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 7.8 HIGH |
| The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS security mechanisms | |||||
| CVE-2024-33655 | 2026-06-17 | N/A | 7.5 HIGH | ||
| The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue. | |||||
| CVE-2024-33654 | 1 Siemens | 1 Simcenter Femap | 2026-06-17 | N/A | 7.8 HIGH |
| A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. | |||||
| CVE-2024-33653 | 1 Siemens | 1 Simcenter Femap | 2026-06-17 | N/A | 7.8 HIGH |
| A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. | |||||
| CVE-2024-33652 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1. | |||||
