Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.3 CVE-2024-39811 Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of pri… Mitigation only Fix from $1,6002024-11-13 MEDIUM 6.1 CVE-2024-37027 Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable … Oneapi Base Toolkit 2024.2 / 2024.2.0+ Fix from $1,6002024-11-13 MEDIUM 6.7 CVE-2024-36482 Improper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalation of priv… Computing Improvement Program 2.4.10852+ Fix from $1,6002024-11-13 HIGH 8.2 CVE-2024-36282 Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to p… Mitigation only Fix from $1,9502024-11-13 MEDIUM 5.5 CVE-2024-36284 Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escal… Mitigation only Fix from $1,6002024-11-13 MEDIUM 6.5 CVE-2024-32048 Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user … Mitigation only Fix from $1,6002024-11-13 MEDIUM 5.5 CVE-2024-32485 Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of se… Virtual Raid On Cpu 8.6.0.2003+ Fix from $1,6002024-11-13 HIGH 7.5 CVE-2024-31154 Improper input validation in UEFI firmware for some Intel(R) Server S2600BPBR may allow a privileged user to potentially enable escalation of privile… Mitigation only Fix from $1,9502024-11-13 HIGH 7.5 CVE-2024-31158 Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation … Mitigation only Fix from $1,9502024-11-13 HIGH 7.5 CVE-2024-28028 Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable esc… Mitigation only Fix from $1,9502024-11-13 MEDIUM 5.7 CVE-2024-28049 Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products before version 23.40… Killer 23.40.0+ Fix from $1,6002024-11-13 MEDIUM 6.5 CVE-2024-24984 Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to pote… Mitigation only Fix from $1,6002024-11-13 MEDIUM 6.6 CVE-2024-23198 Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products before version 23.40 may allo… Killer 23.40.0+ Fix from $1,6002024-11-13 MEDIUM 6.5 CVE-2024-8936 CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-… No fix yet Fix from $1,6002024-11-13 HIGH 7.5 CVE-2024-49033 Microsoft Word Security Feature Bypass Vulnerability 365 Apps Patch available Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-21974 Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execu… Ryzen Ai Software 1.2+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-21975 Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execu… Ryzen Ai Software 1.2+ Fix from $1,9502024-11-12 HIGH 8.8 CVE-2024-21976 Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execu… Mitigation only Fix from $1,9502024-11-12 MEDIUM 5.5 CVE-2024-21949 Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system c… Ryzen Ai Software 1.2+ Fix from $1,6002024-11-12 HIGH 8.4 CVE-2024-10944 A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improp… Mitigation only Fix from $1,9502024-11-12 CRITICAL 9.9 CVE-2024-50386 Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instan… Cloudstack 4.18.2.5 / 4.19.1.3+ Fix from $2,3002024-11-12 MEDIUM 5.3 CVE-2024-39281 The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator. Mitigation only Fix from $1,6002024-11-12 HIGH 7.8 CVE-2024-37365 A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory all… Factorytalk View Mitigation only Fix from $1,9502024-11-12 CRITICAL 9.8 CVE-2024-50557 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-… Ruggedcom Rm1224 Lte\(4g\) Eu Firmware 8.2+ Fix from $2,3002024-11-12 MEDIUM 5.5 CVE-2024-11079 A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and… Mitigation only Fix from $1,6002024-11-12 MEDIUM 5.8 CVE-2024-23983 Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules. No fix yet Fix from $1,6002024-11-11 HIGH 7.5 CVE-2023-1973 A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted re… Mitigation only Fix from $1,9502024-11-07 HIGH 7.5 CVE-2024-20484 A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo… Enterprise Chat And Email 12.5 / 12.6+ Fix from $1,9502024-11-06 HIGH 7.2 CVE-2024-49774 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functio… Suitecrm 7.14.6 / 8.7.1+ Fix from $1,9502024-11-05 HIGH 8.8 CVE-2024-50333 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written … Suitecrm 7.14.6 / 8.7.1+ Fix from $1,9502024-11-05