Vulnerabilities (CVE)

Total 396887 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33023 1 Qualcomm 314 Ar8035, Ar8035 Firmware, Csra6620 and 311 more 2026-06-17 N/A 8.4 HIGH
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
CVE-2024-33022 1 Qualcomm 248 Ar8035, Ar8035 Firmware, Csra6620 and 245 more 2026-06-17 N/A 8.4 HIGH
Memory corruption while allocating memory in HGSL driver.
CVE-2024-33021 1 Qualcomm 276 Ar8035, Ar8035 Firmware, Csra6620 and 273 more 2026-06-17 N/A 8.4 HIGH
Memory corruption while processing IOCTL call to set metainfo.
CVE-2024-33020 1 Qualcomm 196 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 193 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while processing TID-to-link mapping IE elements.
CVE-2024-33019 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-33018 1 Qualcomm 302 Ar8035, Ar8035 Firmware, Csr8811 and 299 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
CVE-2024-33016 1 Qualcomm 666 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 663 more 2026-06-17 N/A 6.8 MEDIUM
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-33015 1 Qualcomm 390 Ar8035, Ar8035 Firmware, Csr8811 and 387 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
CVE-2024-33014 1 Qualcomm 650 315 5g Iot Modem, 315 5g Iot Modem Firmware, 860 Mobile Platform and 647 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33013 1 Qualcomm 340 Ar8035, Ar8035 Firmware, Csr8811 and 337 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
CVE-2024-33012 1 Qualcomm 498 Ar8035, Ar8035 Firmware, Ar9380 and 495 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
CVE-2024-33011 1 Qualcomm 498 Ar8035, Ar8035 Firmware, Ar9380 and 495 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
CVE-2024-33010 1 Qualcomm 496 Ar8035, Ar8035 Firmware, Ar9380 and 493 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-33009 2026-06-17 N/A 4.2 MEDIUM
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
CVE-2024-33008 2026-06-17 N/A 4.9 MEDIUM
SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.
CVE-2024-33007 2026-06-17 N/A 3.5 LOW
PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.
CVE-2024-33006 2026-06-17 N/A 9.6 CRITICAL
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. 
CVE-2024-33005 1 Sap 4 Content Server, Netweaver Abap, Netweaver Java and 1 more 2026-06-17 N/A 6.3 MEDIUM
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the integrity and availability of the applications.
CVE-2024-33004 1 Sap 1 Businessobjects Business Intelligence Platform 2026-06-17 N/A 4.3 MEDIUM
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.
CVE-2024-33003 1 Sap 1 Commerce Cloud 2026-06-17 N/A 7.4 HIGH
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.