Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2024-11697

    When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, T... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Nov. 26, 2024
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2024-11696

    The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the si... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Nov. 26, 2024
    • Modified: Jun. 24, 2025
  • 5.4

    MEDIUM
    CVE-2024-11695

    A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 1... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Nov. 26, 2024
    • Modified: Apr. 03, 2025
  • 6.1

    MEDIUM
    CVE-2024-11694

    Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Nov. 26, 2024
    • Modified: Jun. 24, 2025
  • 9.8

    CRITICAL
    CVE-2024-11693

    The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderb... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Nov. 26, 2024
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2024-11692

    An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Nov. 26, 2024
    • Modified: Apr. 03, 2025
  • 8.8

    HIGH
    CVE-2024-11691

    Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaf... Read more

    Affected Products : firefox firefox_esr thunderbird m1 m1_max m1_pro m1_ultra m2 m2_max m2_pro +8 more products
    • Published: Nov. 26, 2024
    • Modified: Jun. 24, 2025
  • 8.4

    HIGH
    CVE-2018-5852

    An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'... Read more

    • Published: Nov. 26, 2024
    • Modified: Jan. 09, 2025
  • 7.8

    HIGH
    CVE-2018-11816

    Crafted Binder Request Causes Heap UAF in MediaServer... Read more

    • Published: Nov. 26, 2024
    • Modified: Feb. 06, 2025
  • 8.4

    HIGH
    CVE-2017-18307

    Information disclosure possible while audio playback.... Read more

    • Published: Nov. 26, 2024
    • Modified: Jan. 09, 2025
  • 8.4

    HIGH
    CVE-2017-18306

    Information disclosure due to uninitialized variable.... Read more

    • Published: Nov. 26, 2024
    • Modified: Jan. 09, 2025
  • 8.4

    HIGH
    CVE-2016-10408

    QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.... Read more

    • Published: Nov. 26, 2024
    • Modified: Jan. 09, 2025
  • 7.5

    HIGH
    CVE-2024-51569

    Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluet... Read more

    Affected Products : nimble
    • Published: Nov. 26, 2024
    • Modified: Jul. 08, 2025
  • 5.0

    MEDIUM
    CVE-2024-47250

    Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluet... Read more

    Affected Products : nimble
    • Published: Nov. 26, 2024
    • Modified: Jul. 08, 2025
  • 5.0

    MEDIUM
    CVE-2024-47249

    Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severit... Read more

    Affected Products : nimble
    • Published: Nov. 26, 2024
    • Modified: Jul. 08, 2025
  • 6.3

    MEDIUM
    CVE-2024-47248

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: throug... Read more

    Affected Products : nimble
    • Published: Nov. 26, 2024
    • Modified: Jul. 08, 2025
  • 6.5

    MEDIUM
    CVE-2024-38834

    VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.... Read more

    Affected Products : cloud_foundation aria_operations
    • Published: Nov. 26, 2024
    • Modified: May. 14, 2025
  • 6.8

    MEDIUM
    CVE-2024-38833

    VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.... Read more

    Affected Products : cloud_foundation aria_operations
    • Published: Nov. 26, 2024
    • Modified: May. 14, 2025
  • 7.1

    HIGH
    CVE-2024-38832

    VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.... Read more

    Affected Products : cloud_foundation aria_operations
    • Published: Nov. 26, 2024
    • Modified: May. 14, 2025
  • 7.8

    HIGH
    CVE-2024-38831

    VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMwa... Read more

    Affected Products : cloud_foundation aria_operations
    • Published: Nov. 26, 2024
    • Modified: May. 14, 2025
Showing 20 of 291395 Results