Vulnerabilities (CVE)

Total 398478 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23362 1 Qualcomm 464 9205 Lte Modem, 9205 Lte Modem Firmware, Aqt1000 and 461 more 2026-06-17 N/A 7.1 HIGH
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23360 1 Qualcomm 26 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 23 more 2026-06-17 N/A 8.4 HIGH
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
CVE-2024-23359 1 Qualcomm 322 205 Mobile Platform, 205 Mobile Platform Firmware, 315 5g Iot Modem and 319 more 2026-06-17 N/A 8.2 HIGH
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23358 1 Qualcomm 106 205 Mobile Platform, 205 Mobile Platform Firmware, Apq8017 and 103 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-23357 1 Qualcomm 484 215 Mobile Platform, 215 Mobile Platform Firmware, Apq8017 and 481 more 2026-06-17 N/A 6.2 MEDIUM
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2024-23356 1 Qualcomm 420 Aqt1000, Aqt1000 Firmware, Ar8031 and 417 more 2026-06-17 N/A 7.8 HIGH
Memory corruption during session sign renewal request calls in HLOS.
CVE-2024-23355 1 Qualcomm 284 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 281 more 2026-06-17 N/A 7.8 HIGH
Memory corruption when keymaster operation imports a shared key.
CVE-2024-23354 1 Qualcomm 152 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 149 more 2026-06-17 N/A 8.4 HIGH
Memory corruption when the IOCTL call is interrupted by a signal.
CVE-2024-23353 1 Qualcomm 498 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 495 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-23352 1 Qualcomm 210 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 207 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
CVE-2024-23351 1 Qualcomm 188 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 185 more 2026-06-17 N/A 8.4 HIGH
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
CVE-2024-23350 1 Qualcomm 50 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 47 more 2026-06-17 N/A 6.5 MEDIUM
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
CVE-2024-23349 1 Apache 1 Answer 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
CVE-2024-23348 1 Appleple 1 A-blog Cms 2026-06-17 N/A 8.8 HIGH
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker to execute arbitrary JavaScript code by uploading a specially crafted SVG file.
CVE-2024-23347 1 Facebook 1 Meta Spark Studio 2026-06-17 N/A 7.8 HIGH
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
CVE-2024-23346 1 Materialsvirtuallab 1 Pymatgen 2026-06-17 N/A 9.3 CRITICAL
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.
CVE-2024-23345 1 Networktocode 1 Nautobot 2026-06-17 N/A 7.1 HIGH
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2.
CVE-2024-23344 1 Enalean 1 Tuleap 2026-06-17 N/A 5.3 MEDIUM
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.
CVE-2024-23342 1 Tlsfuzzer 1 Ecdsa 2026-06-17 N/A 7.4 HIGH
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
CVE-2024-23341 1 Ithuan 1 Tuitse-tsusin 2026-06-17 N/A 6.1 MEDIUM
TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and the Roman characters. Prior to version 1.3.2, when using `tuitse_html` without quoting the input, there is a html injection vulnerability. Version 1.3.2 contains a patch for the issue. As a workaround, sanitize Taigi input with HTML quotation.