Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Emui MEDIUM 5.5
CVE-2024-51529

Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

No fix yet
Fix from $1,600 2024-11-05
Emui MEDIUM 5.5
CVE-2024-51530

LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2024-11-05
Harmonyos MEDIUM 5.5
CVE-2024-51519

Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2024-11-05
Harmonyos MEDIUM 5.5
CVE-2024-51520

Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2024-11-05
Harmonyos MEDIUM 5.5
CVE-2024-51511

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availabil…

Mitigation only
Fix from $1,600 2024-11-05
Harmonyos MEDIUM 5.5
CVE-2024-51512

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availabil…

No fix yet
Fix from $1,600 2024-11-05
Harmonyos MEDIUM 5.5
CVE-2024-51514

Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confi…

No fix yet
Fix from $1,600 2024-11-05
Wcn3660b Firmware MEDIUM 6.7
CVE-2024-33031

Memory corruption while processing the update SIM PB records request.

Patch available
Fix from $1,600 2024-11-04
Wsa8835 Firmware MEDIUM 6.7
CVE-2024-23386

memory corruption when WiFi display APIs are invoked with large random inputs.

Patch available
Fix from $1,600 2024-11-04
Wbr 6012 Firmware HIGH 7.5
CVE-2024-33700

The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to caus…

No fix yet
Fix from $1,950 2024-10-30
Mf258k Pro Firmware HIGH 8.8
CVE-2024-22065

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent…

Mitigation only
Fix from $1,950 2024-10-29
Squid HIGH 7.5
CVE-2024-45802EPSS 48%

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource Durin…

Fix: 6.10+
Fix from $1,950 2024-10-28
Unclassified HIGH 7.8
CVE-2024-0127

NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest O…

Mitigation only
Fix from $1,950 2024-10-26
Unclassified HIGH 8.2
CVE-2024-0126

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successfu…

Mitigation only
Fix from $1,950 2024-10-26
Zitadel CRITICAL 9.1
CVE-2024-49753

Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in …

Fix: 2.58.7 / 2.59.5+
Fix from $2,300 2024-10-25
Adaptive Security Appliance Software HIGH 8.6
CVE-2024-20495

A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwar…

Mitigation only
Fix from $1,950 2024-10-23
Secure Firewall Management Center MEDIUM 5.5
CVE-2024-20274

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…

Mitigation only
Fix from $1,600 2024-10-23
Unclassified CRITICAL 9.2
CVE-2024-48919

Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via Cursor's Terminal Cmd-K/Ctrl…

Mitigation only
Fix from $2,300 2024-10-22
Nginx Ui CRITICAL 9.8
CVE-2024-49368EPSS 27%

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the…

Fix: after 1.9.9-4
Fix from $2,300 2024-10-21
Unclassified HIGH 8.1
CVE-2024-49361

ACON is a widely-used library of tools for machine learning that focuses on adaptive correlation optimization. A potential vulnerability has been ide…

Mitigation only
Fix from $1,950 2024-10-18
Unclassified HIGH 8.1
CVE-2024-48918

RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prior to 1.1.0 contain a vulnerab…

Patch available
Fix from $1,950 2024-10-16
Unclassified HIGH 8.9
CVE-2024-9348

Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.

Mitigation only
Fix from $1,950 2024-10-16
Cloudstack HIGH 8.5
CVE-2024-45219

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as …

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
Unclassified CRITICAL 9.1
CVE-2024-48914EPSS 60%

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an a…

Patch available
Fix from $2,300 2024-10-15
Controllogix 5580 Firmware HIGH 7.5
CVE-2024-6207

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP messa…

Fix: 33.017 / 34.014+
Fix from $1,950 2024-10-14
Loadmaster CRITICAL 9.8
CVE-2024-8755

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product …

Fix: 7.2.61.0+
Fix from $2,300 2024-10-11
Commerce HIGH 7.6
CVE-2024-45117

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lea…

Mitigation only
Fix from $1,950 2024-10-10
Livewire CRITICAL 9.8
CVE-2024-47823

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and …

Fix: 2.12.7 / 3.5.2+
Fix from $2,300 2024-10-08
Windows Server 2008 HIGH 8.8
CVE-2024-43611

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08
Windows Server 2008 HIGH 8.8
CVE-2024-43592

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08