Latest CVE Feed
-
8.8
HIGHCVE-2024-23973
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HTTP GET req... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-23971
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handlin... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-23970
This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2024-23969
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchn... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-23968
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToS... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-23934
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. User interaction is required to exp... Read more
Affected Products : xav-ax5500_firmware- Published: Sep. 23, 2024
- Modified: Aug. 26, 2025
-
6.8
MEDIUMCVE-2024-23933
Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not requ... Read more
Affected Products : xav-ax5500_firmware- Published: Sep. 23, 2024
- Modified: Aug. 26, 2025
-
6.5
MEDIUMCVE-2024-23930
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Med... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2024-23159
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
7.8
HIGHCVE-2024-23158
A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the conte... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23157
A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execut... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
7.8
HIGHCVE-2024-23154
A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code i... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23153
A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context o... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
7.8
HIGHCVE-2024-23152
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context ... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23150
A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in ... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
7.8
HIGHCVE-2024-23149
A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the contex... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23148
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execut... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23147
A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabi... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23146
A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arb... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-23145
A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of... Read more
- Published: Jun. 25, 2024
- Modified: Aug. 26, 2025