Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Xeon E 2314 Firmware HIGH 7.8
CVE-2022-33894

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege…

Mitigation only
Fix from $1,950 2023-05-10
Lapqc71a Firmware HIGH 7.8
CVE-2022-34147

Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC Performance Mini …

Mitigation only
Fix from $1,950 2023-05-10
Virtual Raid On Cpu MEDIUM 5.5
CVE-2022-25976

Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of ser…

Fix: 7.7.6.1003+
Fix from $1,600 2023-05-10
Nuc8cchb Firmware MEDIUM 6.7
CVE-2022-28699

Improper input validation for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local acc…

Patch available
Fix from $1,600 2023-05-10
Nuc5cpyh Firmware MEDIUM 6.0
CVE-2022-32577

Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable informa…

Patch available
Fix from $1,600 2023-05-10
Circl HIGH 8.2
CVE-2023-1732

When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In…

Fix: 1.3.3+
Fix from $1,950 2023-05-10
Ryzen 5300g Firmware CRITICAL 9.1
CVE-2021-46754

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloa…

Mitigation only
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.1
CVE-2021-46756

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or A…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 6600h Firmware HIGH 8.8
CVE-2021-46773

Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code exe…

No fix yet
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.1
CVE-2021-46762

Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.

Mitigation only
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware HIGH 8.8
CVE-2021-46769

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code e…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware MEDIUM 6.8
CVE-2021-46775

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss o…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2022-23818

Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.

Mitigation only
Fix from $1,950 2023-05-09
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2023-24950EPSS 67%

Microsoft SharePoint Server Spoofing Vulnerability

Patch available
Fix from $1,600 2023-05-09
Windows 10 1507 HIGH 7.5
CVE-2023-29335

Microsoft Word Security Feature Bypass Vulnerability

Fix: 10.0.10240.19926 / 10.0.14393.5921+
Fix from $1,950 2023-05-09
Ipados MEDIUM 5.5
CVE-2023-28200

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Mon…

Fix: 11.7.5 / 12.6.4+
Fix from $1,600 2023-05-08
Ipados MEDIUM 5.5
CVE-2023-27961

Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS …

Fix: 9.4 / 11.7.5+
Fix from $1,600 2023-05-08
Brpc CRITICAL 9.8
CVE-2023-31039

Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha…

Fix: 1.5.0+
Fix from $2,300 2023-05-08
Django CRITICAL 9.8
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl…

Fix: 3.2.19 / 4.1.9+
Fix from $2,300 2023-05-07
Elastic Storage System MEDIUM 5.5
CVE-2023-30434

IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3…

Fix: 6.1.2.6 / 6.1.6.1+
Fix from $1,600 2023-05-05
Mq Appliance MEDIUM 6.5
CVE-2022-43919

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. …

Fix: 9.2.0.10 / 9.2.5.7+
Fix from $1,600 2023-05-05
Android CRITICAL 9.8
CVE-2023-21494

Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attacker…

Mitigation only
Fix from $2,300 2023-05-04
Android HIGH 7.8
CVE-2023-21498

Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite …

Mitigation only
Fix from $1,950 2023-05-04
Android HIGH 7.8
CVE-2023-21501

Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2023-05-04
Android HIGH 7.8
CVE-2023-21502

Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation…

Mitigation only
Fix from $1,950 2023-05-04
Android CRITICAL 9.8
CVE-2023-21503

Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to …

Mitigation only
Fix from $2,300 2023-05-04
Android CRITICAL 9.8
CVE-2023-21504

Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause…

Mitigation only
Fix from $2,300 2023-05-04
Gin HIGH 7.3
CVE-2023-26125

Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially …

Fix: 1.9.0+
Fix from $1,950 2023-05-04
Streampark CRITICAL 9.1
CVE-2022-46365

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-0683

A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,950 2023-05-01