Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Insydeh2o HIGH 8.2
CVE-2022-35893

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver a…

Fix: 05.09.37 / 05.17.37+
Fix from $1,950 2022-09-23
Mac Os X MEDIUM 5.5
CVE-2022-32786

An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, m…

Fix: 10.15.7 / 11.6.8+
Fix from $1,600 2022-09-23
Mac Os X HIGH 7.1
CVE-2022-32797

This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. P…

Fix: 10.15.7 / 11.6.8+
Fix from $1,950 2022-09-23
macOS MEDIUM 5.5
CVE-2022-26707

An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS Monterey 12.4. A user may be a…

Fix: 12.4+
Fix from $1,600 2022-09-23
Common Cryptographic Architecture MEDIUM 5.5
CVE-2022-22423

IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to im…

Fix: 5.7.12 / 7.3.44+
Fix from $1,600 2022-09-23
Pulsar MEDIUM 6.5
CVE-2022-24280

Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from…

Fix: 2.7.5 / 2.8.3+
Fix from $1,600 2022-09-23
Hcl Digital Experience MEDIUM 5.4
CVE-2021-27774

User input included in error response, which could be used in a phishing attack.

Mitigation only
Fix from $1,600 2022-09-22
Insydeh2o MEDIUM 6.0
CVE-2022-35896

An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can dump SMRA…

Fix: after 5.5
Fix from $1,600 2022-09-22
Cv81 Wdm Fw Firmware HIGH 7.5
CVE-2022-37395

A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versi…

Mitigation only
Fix from $1,950 2022-09-20
Bigfileagent HIGH 8.8
CVE-2022-23766

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to b…

Fix: 1.0.1.9+
Fix from $1,950 2022-09-19
Tensorflow HIGH 7.5
CVE-2022-36017

TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requested_output_min`, `requested_out…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-36027

TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel weight quantization the convert…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35979

TensorFlow is an open source platform for machine learning. If `QuantizedRelu` or `QuantizedRelu6` are given nonscalar inputs for `min_features` or `…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35982

TensorFlow is an open source platform for machine learning. If `SparseBincount` is given inputs for `indices`, `values`, and `dense_shape` that do no…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35986

TensorFlow is an open source platform for machine learning. If `RaggedBincount` is given an empty input tensor `splits`, it results in a segfault tha…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35966

TensorFlow is an open source platform for machine learning. If `QuantizedAvgPool` is given `min_input` or `max_input` tensors of a nonzero rank, it r…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35967

TensorFlow is an open source platform for machine learning. If `QuantizedAdd` is given `min_input` or `max_input` tensors of a nonzero rank, it resul…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35970

TensorFlow is an open source platform for machine learning. If `QuantizedInstanceNorm` is given `x_min` or `x_max` tensors of a nonzero rank, it resu…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35972

TensorFlow is an open source platform for machine learning. If `QuantizedBiasAdd` is given `min_input`, `max_input`, `min_bias`, `max_bias` tensors o…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35973

TensorFlow is an open source platform for machine learning. If `QuantizedMatMul` is given nonscalar input for: `min_a`, `max_a`, `min_b`, or `max_b` …

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35974

TensorFlow is an open source platform for machine learning. If `QuantizeDownAndShrinkRange` is given nonscalar inputs for `input_min` or `input_max`,…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35964

TensorFlow is an open source platform for machine learning. The implementation of `BlockLSTMGradV2` does not fully validate its inputs. This results …

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Emui CRITICAL 9.8
CVE-2021-40017

The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory …

Mitigation only
Fix from $2,300 2022-09-16
Illustrator HIGH 7.8
CVE-2022-38408

Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result i…

Fix: after 26.4
Fix from $1,950 2022-09-16
Configuration Manager HIGH 7.8
CVE-2022-35415

An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially enable escalation of privilege…

Fix: 22.5.0+
Fix from $1,950 2022-09-16
Kubevirt MEDIUM 6.5
CVE-2022-1798

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arb…

Fix: 0.55.1+
Fix from $1,600 2022-09-15
Video Management Systems Firmware HIGH 7.5
CVE-2022-3001

This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at…

Fix: 40.7.0.79+
Fix from $1,950 2022-09-15
Microscada X Sys600 HIGH 7.5
CVE-2022-29492

Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro S…

Fix: 10.4+
Fix from $1,950 2022-09-14
Microscada X Sys600 HIGH 7.5
CVE-2022-29922

Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type i…

Fix: 10.4+
Fix from $1,950 2022-09-14
Android HIGH 7.8
CVE-2022-20392

In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to imp…

Patch available
Fix from $1,950 2022-09-13