Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2021-0071 Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalati… Ax210 Firmware 22.40+ Fix from $1,9502021-11-17 HIGH 8.1 CVE-2021-0078 Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to p… Ax210 Firmware 22.40+ Fix from $1,9502021-11-17 MEDIUM 6.5 CVE-2021-0079 Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to p… Ax210 Firmware 22.40+ Fix from $1,6002021-11-17 HIGH 7.8 CVE-2021-26331 AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary cod… Epyc 7003 Firmware Mitigation only Fix from $1,9502021-11-16 HIGH 7.8 CVE-2020-12944 Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution. Epyc 7601 Firmware Mitigation only Fix from $1,9502021-11-16 HIGH 7.1 CVE-2020-12946 Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service. Epyc 7f72 Firmware Mitigation only Fix from $1,9502021-11-16 HIGH 7.8 CVE-2020-12961 A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Ma… Epyc 7003 Firmware Mitigation only Fix from $1,9502021-11-16 MEDIUM 5.5 CVE-2021-26321 Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. Epyc 7601 Firmware Mitigation only Fix from $1,6002021-11-16 HIGH 7.8 CVE-2021-26323 Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity. Epyc 7232p Firmware Mitigation only Fix from $1,9502021-11-16 MEDIUM 5.5 CVE-2021-26325 Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service. Epyc 7232p Firmware Mitigation only Fix from $1,6002021-11-16 MEDIUM 5.5 CVE-2021-26327 Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality. Epyc 7003 Firmware Mitigation only Fix from $1,6002021-11-16 HIGH 8.3 CVE-2021-42114 Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attack… Ddr4 Sdram Firmware No fix yet Fix from $1,9502021-11-16 MEDIUM 5.5 CVE-2020-12960 AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS). Radeon Software 21.4.1+ Fix from $1,6002021-11-15 HIGH 7.8 CVE-2020-12929 Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass secu… Radeon Software 20.11.2+ Fix from $1,9502021-11-15 MEDIUM 6.7 CVE-2021-36323 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi… Alienware 13 R3 Firmware 1.0.9 / 1.10.0+ Fix from $1,6002021-11-12 MEDIUM 6.7 CVE-2021-36324 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi… Alienware 13 R3 Firmware 1.0.9 / 1.10.0+ Fix from $1,6002021-11-12 MEDIUM 6.7 CVE-2021-36325 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi… Alienware 13 R3 Firmware 1.0.9 / 1.10.0+ Fix from $1,6002021-11-12 MEDIUM 5.5 CVE-2021-3786 A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak … Thinkpad X380 Yoga Firmware 2020-10-31 / 2021-10-25+ Fix from $1,6002021-11-12 MEDIUM 6.7 CVE-2021-3843 A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privilege… Thinkpad 11e 3rd Gen Firmware after 1.31 Fix from $1,6002021-11-12 MEDIUM 6.7 CVE-2021-3599 A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access an… Thinkpad X380 Yoga Firmware 2020-10-31 / 2021-10-25+ Fix from $1,6002021-11-12 MEDIUM 6.7 CVE-2021-3719 A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCent… Thinkcentre E93 Firmware Mitigation only Fix from $1,6002021-11-12 HIGH 7.8 CVE-2021-30254 Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdr… Apq8009 Firmware Mitigation only Fix from $1,9502021-11-12 HIGH 7.2 CVE-2021-34417 The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meetin… Zoom On Premise Meeting Connector Controller 2.5.5496.20210703 / 3.8.45.20210703+ Fix from $1,9502021-11-11 MEDIUM 6.5 CVE-2021-3911 If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. Debian Linux 1.3.0+ Fix from $1,6002021-11-11 CRITICAL 9.8 CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr… Debian Linux 1.3.0+ Fix from $2,3002021-11-11 HIGH 7.5 CVE-2021-3910 OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character). Debian Linux 1.4.0+ Fix from $1,9502021-11-11 MEDIUM 5.7 CVE-2021-3572 A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install… Pip 21.1+ Fix from $1,6002021-11-10 MEDIUM 5.5 CVE-2020-10054 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application does not properly handle the im… Simatic Rtls Locating Manager 2.12+ Fix from $1,6002021-11-09 HIGH 7.5 CVE-2021-41772 Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty f… Go 1.16.10 / 1.17.3+ Fix from $1,9502021-11-08 HIGH 8.8 CVE-2021-43406 An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values). Fusionpbx 4.5.30+ Fix from $1,9502021-11-05