Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Outlook HIGH 8.1
CVE-2024-20670

Outlook for Windows Spoofing Vulnerability

Fix: 1.2023.0322.0100+
Fix from $1,950 2024-04-09
Zeppelin MEDIUM 6.5
CVE-2024-31865

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2022-47894

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is …

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 5.3
CVE-2024-31862

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.…

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Emui MEDIUM 6.2
CVE-2023-52385

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,600 2024-04-08
Emui HIGH 7.5
CVE-2024-27896

Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

No fix yet
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2023-52552

Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2024-04-08
Unclassified HIGH 7.5
CVE-2024-27912

A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted L…

Mitigation only
Fix from $1,950 2024-04-05
Instantcms HIGH 7.2
CVE-2024-31212

InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with ad…

No fix yet
Fix from $1,950 2024-04-04
Cloudstack MEDIUM 6.4
CVE-2024-29008

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to…

Fix: 4.18.1.1+
Fix from $1,600 2024-04-04
Telepresence Management Suite MEDIUM 5.4
CVE-2024-20334

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to c…

Fix: 15.13.7+
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-27254

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a spe…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-22360

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 6.5
CVE-2024-25046

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a…

Mitigation only
Fix from $1,600 2024-04-03
Db2 MEDIUM 5.3
CVE-2023-52296

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in funct…

Mitigation only
Fix from $1,600 2024-04-03
Openharmony HIGH 8.8
CVE-2024-29074

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.

Fix: after 3.2.4
Fix from $1,950 2024-04-02
Openharmony HIGH 7.5
CVE-2024-28226

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

Fix: after 4.0
Fix from $1,950 2024-04-02
Ar8035 Firmware CRITICAL 9.8
CVE-2024-21473

Memory corruption while redirecting log file to any file location with any file name.

No fix yet
Fix from $2,300 2024-04-01
C V2x 9150 Firmware HIGH 7.5
CVE-2024-21452

Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.

Mitigation only
Fix from $1,950 2024-04-01
C V2x 9150 Firmware HIGH 7.5
CVE-2024-21453

Transient DOS while decoding message of size that exceeds the available system memory.

No fix yet
Fix from $1,950 2024-04-01
315 5g Iot Modem Firmware HIGH 7.5
CVE-2023-33099

Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.

Mitigation only
Fix from $1,950 2024-04-01
Ar8035 Firmware HIGH 7.5
CVE-2023-33100

Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.

Mitigation only
Fix from $1,950 2024-04-01
Splunk HIGH 8.1
CVE-2024-29946

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let atta…

Fix: 9.0.9 / 9.1.4+
Fix from $1,950 2024-03-27
Ios Xe HIGH 8.6
CVE-2024-20271

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of …

Fix: 8.10.190.0 / 10.6.2.0+
Fix from $1,950 2024-03-27
Unclassified HIGH 8.6
CVE-2023-29134

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.

No fix yet
Fix from $1,950 2024-03-27
Sane Backends HIGH 7.3
CVE-2023-46047

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is d…

No fix yet
Fix from $1,950 2024-03-27
Client Connector HIGH 7.8
CVE-2024-23482

The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.2…

Fix: 4.2.0.241+
Fix from $1,950 2024-03-26
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2425

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the …

No fix yet
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2426

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di…

Mitigation only
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2427

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data…

Mitigation only
Fix from $1,950 2024-03-25