Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Sane Backends HIGH 7.3
CVE-2023-46047

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is d…

No fix yet
Fix from $1,950 2024-03-27
Client Connector HIGH 7.8
CVE-2024-23482

The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.2…

Fix: 4.2.0.241+
Fix from $1,950 2024-03-26
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2425

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the …

No fix yet
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2426

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di…

Mitigation only
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2427

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data…

Mitigation only
Fix from $1,950 2024-03-25
Translate MEDIUM 5.3
CVE-2024-29042

Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker contr…

Fix: 3.0.0+
Fix from $1,600 2024-03-22
Coder HIGH 8.2
CVE-2024-27918

Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in …

Fix: 2.6.1 / 2.7.3+
Fix from $1,950 2024-03-21
Enterprise Server HIGH 7.2
CVE-2024-2443

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.17 / 3.9.12+
Fix from $1,950 2024-03-20
Enterprise Server HIGH 7.2
CVE-2024-2469

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected …

Fix: 3.8.17 / 3.9.12+
Fix from $1,950 2024-03-20
Mq MEDIUM 5.3
CVE-2023-45177

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM…

Fix: 9.0.0.21 / 9.1.0.18+
Fix from $1,600 2024-03-20
Geoserver MEDIUM 6.0
CVE-2024-23634

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerabi…

Fix: 2.23.5 / 2.24.2+
Fix from $1,600 2024-03-20
Geoserver HIGH 7.2
CVE-2023-51444

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerabili…

Fix: 2.23.4+
Fix from $1,950 2024-03-20
Hop Engine MEDIUM 6.5
CVE-2024-24683

Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $1,600 2024-03-19
Poweredge R730 Firmware MEDIUM 6.8
CVE-2024-25942

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potent…

Fix: 2.14.0 / 2.19.0+
Fix from $1,600 2024-03-19
Zitadel MEDIUM 6.1
CVE-2024-28855

ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` inste…

Fix: 2.41.15 / 2.42.15+
Fix from $1,600 2024-03-18
Unclassified MEDIUM 5.9
CVE-2024-25656

Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipm…

Mitigation only
Fix from $1,600 2024-03-18
Vertica CRITICAL 9.8
CVE-2023-7248

Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.  The vulnerability would affect one of V…

Fix: 11.1.1-25 / 12.0.4-19+
Fix from $2,300 2024-03-15
Zephyr HIGH 7.5
CVE-2023-7060

Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the desti…

Fix: 3.6.0+
Fix from $1,950 2024-03-15
Unclassified MEDIUM 6.7
CVE-2023-32633

Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable esc…

Mitigation only
Fix from $1,600 2024-03-14
Ios Xr HIGH 7.4
CVE-2024-20327

A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers …

Fix: 7.9.21 / 7.10.1+
Fix from $1,950 2024-03-13
Unclassified HIGH 7.4
CVE-2024-20318

A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card ne…

Mitigation only
Fix from $1,950 2024-03-13
Tomcat HIGH 7.5
CVE-2024-24549EPSS 23%

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ…

Fix: 8.5.99 / 9.0.86+
Fix from $1,950 2024-03-13
Essential Blocks MEDIUM 5.4
CVE-2024-1854

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Fix: 4.5.2+
Fix from $1,600 2024-03-13
Poweredge T360 Firmware HIGH 8.4
CVE-2024-0161

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileg…

Fix: 1.1.1 / 1.13.2+
Fix from $1,950 2024-03-13
Pulsar CRITICAL 9.9
CVE-2024-27135EPSS 6%

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Pulsar HIGH 8.8
CVE-2024-27894

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referen…

Fix: 2.10.6 / 2.11.4+
Fix from $1,950 2024-03-12
Windows Server 2012 MEDIUM 6.5
CVE-2024-26197

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Fix: 10.0.14393.6796 / 10.0.17763.5576+
Fix from $1,600 2024-03-12
Windows 10 1507 MEDIUM 5.5
CVE-2024-26181

Windows Kernel Denial of Service Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,600 2024-03-12
Windows 10 21h2 HIGH 7.8
CVE-2024-26170EPSS 7%

Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

Fix: 10.0.19044.4170 / 10.0.19045.4170+
Fix from $1,950 2024-03-12
Windows 10 1507 HIGH 7.8
CVE-2024-26173

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,950 2024-03-12