Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ethernet Controller I225 It Firmware MEDIUM 6.0
CVE-2021-33142

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user…

Fix: 1.87 / 29.0.1+
Fix from $1,600 2024-02-23
Ethernet Controller I225 It Firmware MEDIUM 5.3
CVE-2021-33146

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticate…

Fix: 1.87 / 29.0.1+
Fix from $1,600 2024-02-23
Ethernet Controller I225 It Firmware HIGH 7.2
CVE-2021-33161

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user…

Fix: 1.87 / 29.0.1+
Fix from $1,950 2024-02-23
Dolphinscheduler HIGH 8.8
CVE-2024-23320

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.2.1+
Fix from $1,950 2024-02-23
Mjml Python MEDIUM 5.4
CVE-2024-26151

The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mail…

Patch available
Fix from $1,600 2024-02-22
Identityiq HIGH 7.1
CVE-2024-1714

An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or traili…

Mitigation only
Fix from $1,950 2024-02-21
Unclassified HIGH 7.5
CVE-2024-22054

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management …

Mitigation only
Fix from $1,950 2024-02-20
Openolat MEDIUM 5.4
CVE-2024-25973

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit gr…

Fix: 18.1.6+
Fix from $1,600 2024-02-20
Openolat MEDIUM 5.4
CVE-2024-25974

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Cente…

Fix: 18.1.6+
Fix from $1,600 2024-02-20
Zephyr CRITICAL 9.1
CVE-2024-1638

The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write …

Fix: after 3.5.0
Fix from $2,300 2024-02-19
Emui MEDIUM 5.3
CVE-2023-52368

Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.

No fix yet
Fix from $1,600 2024-02-18
Emui HIGH 7.5
CVE-2023-52372

Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affect availability.

Mitigation only
Fix from $1,950 2024-02-18
Android HIGH 7.8
CVE-2024-0021

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener se…

Patch available
Fix from $1,950 2024-02-16
Urlite HIGH 7.5
CVE-2023-51931

An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.

Fix: after 3.1.0
Fix from $1,950 2024-02-16
Android CRITICAL 9.8
CVE-2024-0031

In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead t…

Patch available
Fix from $2,300 2024-02-16
Wolfssl MEDIUM 5.3
CVE-2023-6937

wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS me…

Fix: 5.6.6+
Fix from $1,600 2024-02-15
Acrobat Dc MEDIUM 5.5
CVE-2024-20733

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an appli…

Fix: 20.005.30574 / 23.008.20533+
Fix from $1,600 2024-02-15
Smartfabric Os10 CRITICAL 9.8
CVE-2023-32462

Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remot…

Fix: 10.5.2.12 / 10.5.3.8+
Fix from $2,300 2024-02-15
Enterprise Sonic Distribution CRITICAL 9.8
CVE-2023-32484

Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remot…

Fix: 3.5.5 / 4.0.6+
Fix from $2,300 2024-02-15
Sgx Dcap MEDIUM 5.5
CVE-2023-42776

Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially en…

Fix: 1.19.100.3+
Fix from $1,600 2024-02-14
Killer MEDIUM 6.5
CVE-2023-34983

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated…

Fix: 3.1423.712 / 22.240+
Fix from $1,600 2024-02-14
Killer MEDIUM 6.5
CVE-2023-28374

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated…

Fix: 3.1423.712 / 22.240+
Fix from $1,600 2024-02-14
Killer MEDIUM 6.7
CVE-2023-25951

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user …

Fix: 3.1423.712 / 22.240+
Fix from $1,600 2024-02-14
Thunderbolt Dch Driver HIGH 7.7
CVE-2023-22342

Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially e…

Fix: 88+
Fix from $1,950 2024-02-14
Meeting Software Development Kit MEDIUM 6.5
CVE-2024-24695

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticate…

Fix: 5.15.15 / 5.16.5+
Fix from $1,600 2024-02-14
Meeting Software Development Kit MEDIUM 6.5
CVE-2024-24696

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticate…

Fix: 5.15.15 / 5.16.12+
Fix from $1,600 2024-02-14
Enterprise Server CRITICAL 9.1
CVE-2024-1369

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1372

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1374

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1378

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13