Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Emui CRITICAL 9.8
CVE-2021-22431

There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds …

No fix yet
Fix from $2,300 2022-02-25
Fedora HIGH 8.8
CVE-2022-0729

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

Fix: 8.2.4440 / 13.0+
Fix from $1,950 2022-02-23
Dicom Viewer Pro HIGH 7.8
CVE-2022-24063

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 13.2.0.21165. User interacti…

Fix: 11.9.2+
Fix from $1,950 2022-02-18
Microstation HIGH 7.8
CVE-2021-46598

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User inter…

Fix: 10.16.02+
Fix from $1,950 2022-02-18
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Fedora CRITICAL 9.8
CVE-2021-3657

A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IM…

Fix: 1.4.4+
Fix from $2,300 2022-02-18
Mruby MEDIUM 5.5
CVE-2022-0614

Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.

Fix: 3.2+
Fix from $1,600 2022-02-16
Njs CRITICAL 9.8
CVE-2021-46461

njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.

Fix: after 0.7.0
Fix from $2,300 2022-02-14
Fedora HIGH 7.8
CVE-2022-0554

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4327 / 13.0+
Fix from $1,950 2022-02-10
Emui CRITICAL 9.8
CVE-2021-39997

There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may cause out-o…

No fix yet
Fix from $2,300 2022-02-09
365 Apps MEDIUM 5.5
CVE-2022-22716

Microsoft Excel Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2022-02-09
Jt2go HIGH 7.8
CVE-2021-44016

A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All version…

Fix: 13.2.0.7 / 13.3.0.1+
Fix from $1,950 2022-02-09
Jt2go HIGH 7.8
CVE-2021-44018

A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All version…

Fix: 13.2.0.7 / 13.3.0.1+
Fix from $1,950 2022-02-09
Simcenter Femap HIGH 7.8
CVE-2021-46153

A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains …

Mitigation only
Fix from $1,950 2022-02-09
Simcenter Femap HIGH 7.8
CVE-2021-46157

A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains …

Mitigation only
Fix from $1,950 2022-02-09
Fedora HIGH 7.1
CVE-2022-0522

Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

Fix: 5.6.2+
Fix from $1,950 2022-02-08
Fedora HIGH 7.1
CVE-2022-0519

Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

Fix: 5.6.2+
Fix from $1,950 2022-02-08
Fedora HIGH 7.1
CVE-2022-0521

Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.

Fix: 5.6.2+
Fix from $1,950 2022-02-08
Insydeh2o HIGH 8.2
CVE-2021-41837

An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM …

Fix: 5.08.41 / 5.16.41+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 8.2
CVE-2021-41838

An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access …

Fix: 5.16.42 / 5.26.42+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 8.2
CVE-2021-41839

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes S…

Fix: 5.16.25 / 5.26.25+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 7.5
CVE-2021-33625

An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EF…

Fix: 5.16.23 / 5.26.23+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 8.2
CVE-2021-33627

An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.…

Fix: 5.08.29 / 5.16.29+
Fix from $1,950 2022-02-03
Stormshield Network Security CRITICAL 9.8
CVE-2021-31617

In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through…

Fix: 2.7.9 / 3.7.21+
Fix from $2,300 2022-01-31
Debian Linux HIGH 7.8
CVE-2022-0351

Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

Fix: 8.2 / 12.6+
Fix from $1,950 2022-01-25
Jerryscript MEDIUM 5.5
CVE-2021-44992

There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.

Patch available
Fix from $1,600 2022-01-25
Precision 5820 Tower Firmware MEDIUM 6.4
CVE-2021-36343

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.5.0 / 1.10.1+
Fix from $1,600 2022-01-24
Precision 7510 Firmware MEDIUM 6.4
CVE-2021-36342

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.5.0 / 1.10.1+
Fix from $1,600 2022-01-24
Moddable Sdk MEDIUM 5.5
CVE-2021-46333

Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.

Patch available
Fix from $1,600 2022-01-20
Gpac MEDIUM 5.5
CVE-2021-45767

GPAC 1.1.0 was discovered to contain an invalid memory address dereference via the function lsr_read_id(). This vulnerability can lead to a Denial of…

No fix yet
Fix from $1,600 2022-01-14