Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ax210 Firmware HIGH 8.1
CVE-2021-0078

Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to p…

Fix: 22.40+
Fix from $1,950 2021-11-17
Ax210 Firmware MEDIUM 6.5
CVE-2021-0079

Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to p…

Fix: 22.40+
Fix from $1,600 2021-11-17
Epyc 7003 Firmware HIGH 7.8
CVE-2021-26331

AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary cod…

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7601 Firmware HIGH 7.8
CVE-2020-12944

Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7f72 Firmware HIGH 7.1
CVE-2020-12946

Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware HIGH 7.8
CVE-2020-12961

A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Ma…

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7601 Firmware MEDIUM 5.5
CVE-2021-26321

Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.

Mitigation only
Fix from $1,600 2021-11-16
Epyc 7232p Firmware HIGH 7.8
CVE-2021-26323

Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7232p Firmware MEDIUM 5.5
CVE-2021-26325

Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.

Mitigation only
Fix from $1,600 2021-11-16
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26327

Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.

Mitigation only
Fix from $1,600 2021-11-16
Ddr4 Sdram Firmware HIGH 8.3
CVE-2021-42114

Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attack…

No fix yet
Fix from $1,950 2021-11-16
Radeon Software MEDIUM 5.5
CVE-2020-12960

AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).

Fix: 21.4.1+
Fix from $1,600 2021-11-15
Radeon Software HIGH 7.8
CVE-2020-12929

Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass secu…

Fix: 20.11.2+
Fix from $1,950 2021-11-15
Alienware 13 R3 Firmware MEDIUM 6.7
CVE-2021-36323

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.9 / 1.10.0+
Fix from $1,600 2021-11-12
Alienware 13 R3 Firmware MEDIUM 6.7
CVE-2021-36324

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.9 / 1.10.0+
Fix from $1,600 2021-11-12
Alienware 13 R3 Firmware MEDIUM 6.7
CVE-2021-36325

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.9 / 1.10.0+
Fix from $1,600 2021-11-12
Thinkpad X380 Yoga Firmware MEDIUM 5.5
CVE-2021-3786

A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak …

Fix: 2020-10-31 / 2021-10-25+
Fix from $1,600 2021-11-12
Thinkpad 11e 3rd Gen Firmware MEDIUM 6.7
CVE-2021-3843

A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privilege…

Fix: after 1.31
Fix from $1,600 2021-11-12
Thinkpad X380 Yoga Firmware MEDIUM 6.7
CVE-2021-3599

A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access an…

Fix: 2020-10-31 / 2021-10-25+
Fix from $1,600 2021-11-12
Thinkcentre E93 Firmware MEDIUM 6.7
CVE-2021-3719

A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCent…

Mitigation only
Fix from $1,600 2021-11-12
Apq8009 Firmware HIGH 7.8
CVE-2021-30254

Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdr…

Mitigation only
Fix from $1,950 2021-11-12
Zoom On Premise Meeting Connector Controller HIGH 7.2
CVE-2021-34417

The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meetin…

Fix: 2.5.5496.20210703 / 3.8.45.20210703+
Fix from $1,950 2021-11-11
Debian Linux MEDIUM 6.5
CVE-2021-3911

If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.

Fix: 1.3.0+
Fix from $1,600 2021-11-11
Debian Linux CRITICAL 9.8
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…

Fix: 1.3.0+
Fix from $2,300 2021-11-11
Debian Linux HIGH 7.5
CVE-2021-3910

OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).

Fix: 1.4.0+
Fix from $1,950 2021-11-11
Pip MEDIUM 5.7
CVE-2021-3572

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install…

Fix: 21.1+
Fix from $1,600 2021-11-10
Simatic Rtls Locating Manager MEDIUM 5.5
CVE-2020-10054

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application does not properly handle the im…

Fix: 2.12+
Fix from $1,600 2021-11-09
Go HIGH 7.5
CVE-2021-41772

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty f…

Fix: 1.16.10 / 1.17.3+
Fix from $1,950 2021-11-08
Fusionpbx HIGH 8.8
CVE-2021-43406

An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).

Fix: 4.5.30+
Fix from $1,950 2021-11-05
Samsung Flow HIGH 7.1
CVE-2021-25509

A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows kno…

Fix: 4.8.5.0+
Fix from $1,950 2021-11-05