Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Latitude 5290 2 In 1 Firmware MEDIUM 6.7
CVE-2024-38483

Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access coul…

Fix: 1.26.0 / 1.32.8+
Fix from $1,600 2024-08-14
Avalanche HIGH 7.2
CVE-2024-37373

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

Mitigation only
Fix from $1,950 2024-08-14
Azure Stack Hub HIGH 7.0
CVE-2024-38201

Azure Stack Hub Elevation of Privilege Vulnerability

Fix: 1.2311.1.22+
Fix from $1,950 2024-08-13
Windows 10 1507 HIGH 7.8
CVE-2024-38196EPSS 6%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20751 / 10.0.14393.7259+
Fix from $1,950 2024-08-13
365 Apps HIGH 8.8
CVE-2024-38189 KEVEPSS 8%

Microsoft Project Remote Code Execution Vulnerability

Fix: 16.0.5461.1001+
Fix from $1,950 2024-08-13
Uprof MEDIUM 5.5
CVE-2023-31366

Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.

Fix: 4.1.424 / 4.2.816+
Fix from $1,600 2024-08-13
Trusted Firmware A MEDIUM 5.8
CVE-2023-31339

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bo…

Fix: 2.10.1 / 2023.2+
Fix from $1,600 2024-08-13
Unclassified HIGH 7.3
CVE-2022-23817

Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/wri…

Mitigation only
Fix from $1,950 2024-08-13
Ruggedcom Rm1224 Lte\(4g\) Eu Firmware HIGH 8.8
CVE-2024-41976

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…

Fix: 8.1+
Fix from $1,950 2024-08-13
Sinec Nms CRITICAL 9.1
CVE-2024-41940

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privilege…

Fix: 3.0+
Fix from $2,300 2024-08-13
Dolphinscheduler HIGH 8.1
CVE-2024-30188EPSS 6%

File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affect…

Fix: 3.2.2+
Fix from $1,950 2024-08-12
Dolphinscheduler HIGH 8.8
CVE-2024-29831

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.2.2+
Fix from $1,950 2024-08-12
Vynamic Security Suite MEDIUM 6.8
CVE-2023-24062

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of t…

Fix: 3.3.0sr12 / 4.0.0sr04+
Fix from $1,600 2024-08-08
Brizy MEDIUM 6.1
CVE-2024-6254

The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to…

Fix: 2.5.2+
Fix from $1,600 2024-08-08
Client Connector CRITICAL 9.8
CVE-2024-23483

An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connec…

Fix: 4.2+
Fix from $2,300 2024-08-06
Unclassified CRITICAL 9.3
CVE-2024-6915

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation th…

Mitigation only
Fix from $2,300 2024-08-05
Epyc 7203 Firmware HIGH 7.9
CVE-2024-21978

Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data…

Mitigation only
Fix from $1,950 2024-08-05
Tcb Servisign HIGH 8.8
CVE-2024-40721

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visit…

Fix: 1.0.24.0318+
Fix from $1,950 2024-08-02
Omnivise T3000 Application Server CRITICAL 9.8
CVE-2024-38879

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 …

Mitigation only
Fix from $2,300 2024-08-02
Tcb Servisign HIGH 8.8
CVE-2024-40720

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visit…

Fix: 1.0.24.0318+
Fix from $1,950 2024-08-02
Neatvnc CRITICAL 9.8
CVE-2024-42458

server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369.

Fix: 0.8.1+
Fix from $2,300 2024-08-02
Drivers Management HIGH 7.8
CVE-2023-1577

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code wit…

Fix: 3.1.1307.1308+
Fix from $1,950 2024-07-31
Pcmanager MEDIUM 5.5
CVE-2017-3772

A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

Fix: 2.6.40.3154+
Fix from $1,600 2024-07-31
Cato Client HIGH 8.8
CVE-2024-6978

Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

Fix: 5.10.34+
Fix from $1,950 2024-07-31
Cato Client HIGH 8.8
CVE-2024-6973

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

Fix: 5.10.34+
Fix from $1,950 2024-07-31
Unclassified HIGH 8.8
CVE-2024-7340

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse …

Patch available
Fix from $1,950 2024-07-31
Nvr4104 4ks2\/l Firmware HIGH 7.5
CVE-2024-39948

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th…

Fix: 4.003.0000000.1.r.240515+
Fix from $1,950 2024-07-31
Nvr4104 4ks2\/l Firmware HIGH 7.5
CVE-2024-39949

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th…

Fix: 4.003.0000000.1.r.240515+
Fix from $1,950 2024-07-31
Nvr4104 4ks2\/l Firmware CRITICAL 9.8
CVE-2024-39950

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate…

Fix: 4.003.0000000.1.r.240515+
Fix from $2,300 2024-07-31
Nvr4104 4ks2\/l Firmware HIGH 7.5
CVE-2024-39944

A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the…

Fix: 4.003.0000000.1.r.240515+
Fix from $1,950 2024-07-31