Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Moodle HIGH 7.5
CVE-2024-34009

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCA…

Fix: 4.3.4+
Fix from $1,950 2024-05-31
Snapd HIGH 8.1
CVE-2024-5138

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap.…

Fix: 2.63.1+
Fix from $1,950 2024-05-31
Moodle MEDIUM 6.2
CVE-2024-33996

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did …

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle CRITICAL 9.8
CVE-2024-33999

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

Fix: 4.3.4+
Fix from $2,300 2024-05-31
Security Verify Access Oidc Provider MEDIUM 5.5
CVE-2024-22338

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. …

Fix: after 23.03
Fix from $1,600 2024-05-31
Qdrant HIGH 7.5
CVE-2024-3584

qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoi…

Fix: 1.9.0+
Fix from $1,950 2024-05-30
Unclassified HIGH 7.5
CVE-2024-3657

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of servi…

No fix yet
Fix from $1,950 2024-05-28
Unclassified MEDIUM 5.7
CVE-2024-2199

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modi…

Mitigation only
Fix from $1,600 2024-05-28
Mjs MEDIUM 5.5
CVE-2024-35384

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.

No fix yet
Fix from $1,600 2024-05-21
Anythingllm HIGH 7.2
CVE-2024-4287

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application…

Fix: 1.0.0+
Fix from $1,950 2024-05-20
Unclassified CRITICAL 9.0
CVE-2024-36053

In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connect…

Mitigation only
Fix from $2,300 2024-05-19
Unclassified HIGH 7.2
CVE-2021-22508

A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL …

Mitigation only
Fix from $1,950 2024-05-17
Edge Gateway 5000 Firmware MEDIUM 6.7
CVE-2024-22429

Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit t…

Fix: 1.18.0 / 1.24.0+
Fix from $1,600 2024-05-17
Zabbix HIGH 8.8
CVE-2024-22120EPSS 77%

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip"…

Fix: 6.0.28 / 6.4.13+
Fix from $1,950 2024-05-17
Unclassified CRITICAL 10.0
CVE-2024-22476EPSS 36%

Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable es…

Mitigation only
Fix from $2,300 2024-05-16
Unclassified HIGH 7.5
CVE-2024-23487

Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged use…

Mitigation only
Fix from $1,950 2024-05-16
Unclassified HIGH 7.5
CVE-2024-24981

Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to en…

Mitigation only
Fix from $1,950 2024-05-16
Unclassified MEDIUM 6.5
CVE-2024-22015

Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to potentially denial of service…

Mitigation only
Fix from $1,600 2024-05-16
Unclassified HIGH 7.2
CVE-2024-22095

Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged u…

Mitigation only
Fix from $1,950 2024-05-16
Unclassified HIGH 7.5
CVE-2024-22382

Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to ena…

Mitigation only
Fix from $1,950 2024-05-16
Media Sdk MEDIUM 5.5
CVE-2023-48368

Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via loc…

Mitigation only
Fix from $1,600 2024-05-16
Tdx Module MEDIUM 6.7
CVE-2023-47855

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalat…

Fix: 1.5.05.46.698+
Fix from $1,600 2024-05-16
Tdx Module HIGH 8.2
CVE-2023-45745

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalat…

Fix: 1.5.05.46.698+
Fix from $1,950 2024-05-16
Unclassified HIGH 8.2
CVE-2023-38654

Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to …

Mitigation only
Fix from $1,950 2024-05-16
Unclassified HIGH 7.2
CVE-2023-28402

Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local ac…

Mitigation only
Fix from $1,950 2024-05-16
Unclassified MEDIUM 5.8
CVE-2023-22662

Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potenti…

Mitigation only
Fix from $1,600 2024-05-16
Factorytalk View CRITICAL 9.8
CVE-2024-4609

A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…

Fix: 11.0+
Fix from $2,300 2024-05-16
Chuanhuchatgpt HIGH 7.5
CVE-2024-4321

A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading …

No fix yet
Fix from $1,950 2024-05-16
Appdynamics MEDIUM 5.5
CVE-2024-20394

A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condi…

Fix: 24.4.0+
Fix from $1,600 2024-05-15
Unclassified HIGH 7.1
CVE-2024-25743

In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signa…

Mitigation only
Fix from $1,950 2024-05-15