Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 6.3
CVE-2024-39811

Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of pri…

Mitigation only
Fix from $1,600 2024-11-13
Oneapi Base Toolkit MEDIUM 6.1
CVE-2024-37027

Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable …

Fix: 2024.2 / 2024.2.0+
Fix from $1,600 2024-11-13
Computing Improvement Program MEDIUM 6.7
CVE-2024-36482

Improper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalation of priv…

Fix: 2.4.10852+
Fix from $1,600 2024-11-13
Unclassified HIGH 8.2
CVE-2024-36282

Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to p…

Mitigation only
Fix from $1,950 2024-11-13
Unclassified MEDIUM 5.5
CVE-2024-36284

Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escal…

Mitigation only
Fix from $1,600 2024-11-13
Unclassified MEDIUM 6.5
CVE-2024-32048

Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user …

Mitigation only
Fix from $1,600 2024-11-13
Virtual Raid On Cpu MEDIUM 5.5
CVE-2024-32485

Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of se…

Fix: 8.6.0.2003+
Fix from $1,600 2024-11-13
Unclassified HIGH 7.5
CVE-2024-31154

Improper input validation in UEFI firmware for some Intel(R) Server S2600BPBR may allow a privileged user to potentially enable escalation of privile…

Mitigation only
Fix from $1,950 2024-11-13
Unclassified HIGH 7.5
CVE-2024-31158

Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation …

Mitigation only
Fix from $1,950 2024-11-13
Unclassified HIGH 7.5
CVE-2024-28028

Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable esc…

Mitigation only
Fix from $1,950 2024-11-13
Killer MEDIUM 5.7
CVE-2024-28049

Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products before version 23.40…

Fix: 23.40.0+
Fix from $1,600 2024-11-13
Unclassified MEDIUM 6.5
CVE-2024-24984

Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to pote…

Mitigation only
Fix from $1,600 2024-11-13
Killer MEDIUM 6.6
CVE-2024-23198

Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products before version 23.40 may allo…

Fix: 23.40.0+
Fix from $1,600 2024-11-13
Unclassified MEDIUM 6.5
CVE-2024-8936

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-…

No fix yet
Fix from $1,600 2024-11-13
365 Apps HIGH 7.5
CVE-2024-49033

Microsoft Word Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2024-11-12
Ryzen Ai Software HIGH 7.8
CVE-2024-21974

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execu…

Fix: 1.2+
Fix from $1,950 2024-11-12
Ryzen Ai Software HIGH 7.8
CVE-2024-21975

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execu…

Fix: 1.2+
Fix from $1,950 2024-11-12
Unclassified HIGH 8.8
CVE-2024-21976

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execu…

Mitigation only
Fix from $1,950 2024-11-12
Ryzen Ai Software MEDIUM 5.5
CVE-2024-21949

Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system c…

Fix: 1.2+
Fix from $1,600 2024-11-12
Unclassified HIGH 8.4
CVE-2024-10944

A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improp…

Mitigation only
Fix from $1,950 2024-11-12
Cloudstack CRITICAL 9.9
CVE-2024-50386

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan…

Fix: 4.18.2.5 / 4.19.1.3+
Fix from $2,300 2024-11-12
Unclassified MEDIUM 5.3
CVE-2024-39281

The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.

Mitigation only
Fix from $1,600 2024-11-12
Factorytalk View HIGH 7.8
CVE-2024-37365

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory all…

Mitigation only
Fix from $1,950 2024-11-12
Ruggedcom Rm1224 Lte\(4g\) Eu Firmware CRITICAL 9.8
CVE-2024-50557

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…

Fix: 8.2+
Fix from $2,300 2024-11-12
Unclassified MEDIUM 5.5
CVE-2024-11079

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and…

Mitigation only
Fix from $1,600 2024-11-12
Unclassified MEDIUM 5.8
CVE-2024-23983

Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.

No fix yet
Fix from $1,600 2024-11-11
Unclassified HIGH 7.5
CVE-2023-1973

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted re…

Mitigation only
Fix from $1,950 2024-11-07
Enterprise Chat And Email HIGH 7.5
CVE-2024-20484

A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo…

Fix: 12.5 / 12.6+
Fix from $1,950 2024-11-06
Suitecrm HIGH 7.2
CVE-2024-49774

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functio…

Fix: 7.14.6 / 8.7.1+
Fix from $1,950 2024-11-05
Suitecrm HIGH 8.8
CVE-2024-50333

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written …

Fix: 7.14.6 / 8.7.1+
Fix from $1,950 2024-11-05