Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iterm2 CRITICAL 9.8
CVE-2022-45872

iTerm2 before 3.4.18 mishandles a DECRQSS response.

Fix: 3.4.18+
Fix from $2,300 2022-11-23
Sourcegraph HIGH 7.8
CVE-2022-41942

Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present i…

Fix: 4.1.0+
Fix from $1,950 2022-11-22
Microscada Pro Sys600 HIGH 7.8
CVE-2022-3388

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an …

Mitigation only
Fix from $1,950 2022-11-21
Hama HIGH 7.5
CVE-2022-45470

missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect t…

Fix: after 1.7.1
Fix from $1,950 2022-11-21
Gpu Display Driver HIGH 7.1
CVE-2022-31616

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user …

Fix: 11.8 / 13.3+
Fix from $1,950 2022-11-19
Gpu Display Driver HIGH 7.8
CVE-2022-31607

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user with basic capabilities can cau…

Fix: 390.154 / 450.203.03+
Fix from $1,950 2022-11-19
Tensorflow HIGH 7.5
CVE-2022-41909

TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a seg…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41908

TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger a `CHECK` fail in `tf.raw_op…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41901

TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape with rank 0 will trigger a `CH…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41898

TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFlow will crash. We have patche…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41899

TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41896

TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greate…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41891

TensorFlow is an open source platform for machine learning. If `tf.raw_ops.TensorListConcat` is given `element_shape=[]`, it results segmentation fau…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Tensorflow HIGH 7.5
CVE-2022-41888

TensorFlow is an open source platform for machine learning. When running on GPU, `tf.image.generate_bounding_box_proposals` receives a `scores` input…

Fix: 2.8.4 / 2.9.3+
Fix from $1,950 2022-11-18
Infraskope Siem\+ HIGH 8.2
CVE-2022-24037

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical …

Fix: 7.10.00+
Fix from $1,950 2022-11-18
Halo Firmware CRITICAL 9.8
CVE-2022-36784

Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /ap…

Mitigation only
Fix from $2,300 2022-11-17
Android MEDIUM 6.7
CVE-2022-20459

In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead to local escalation of privil…

No fix yet
Fix from $1,600 2022-11-17
Btcd MEDIUM 6.5
CVE-2022-39389

Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerabl…

Fix: 0.15.4 / 0.23.3+
Fix from $1,600 2022-11-17
Fedora MEDIUM 5.7
CVE-2022-39318

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malic…

Fix: 2.9.0+
Fix from $1,600 2022-11-16
Cloud Pak For Security HIGH 8.1
CVE-2022-38385

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unaut…

Fix: after 1.10.2.0
Fix from $1,950 2022-11-15
Adaptive Security Appliance Software MEDIUM 6.5
CVE-2022-20924

A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre…

No fix yet
Fix from $1,600 2022-11-15
Manageengine Servicedesk Plus Msp HIGH 8.8
CVE-2022-40773

Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to …

Fix: 10.6 / 11.0+
Fix from $1,950 2022-11-12
Mq MEDIUM 6.5
CVE-2022-31772

IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT c…

Patch available
Fix from $1,600 2022-11-11
Nuc 11 Compute Element Cm11ebi38w Firmware HIGH 7.8
CVE-2022-38099

Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to pote…

Mitigation only
Fix from $1,950 2022-11-11
Nuc 11 Performance Kit Nuc11pahi30z Firmware MEDIUM 6.7
CVE-2022-33176

Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357…

Patch available
Fix from $1,600 2022-11-11
Nuc Board De3815tybe Firmware MEDIUM 6.7
CVE-2022-34152

Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to poten…

Patch available
Fix from $1,600 2022-11-11
Server Platform Services Firmware MEDIUM 5.5
CVE-2022-29466

Improper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated user to potentially enable den…

Mitigation only
Fix from $1,600 2022-11-11
S2600wf Firmware MEDIUM 6.7
CVE-2022-30542

Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System R2000WF f…

Fix: after 02.01.0014
Fix from $1,600 2022-11-11
Xmm 7560 Firmware HIGH 8.2
CVE-2022-28126

Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially…

Mitigation only
Fix from $1,950 2022-11-11
Xmm 7560 Firmware HIGH 7.2
CVE-2022-28611

Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially…

Mitigation only
Fix from $1,950 2022-11-11