Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2024-51529 Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability. Emui No fix yet Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51530 LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51519 Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51520 Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51511 Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availabil… Harmonyos Mitigation only Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51512 Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availabil… Harmonyos No fix yet Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51514 Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confi… Harmonyos No fix yet Fix from $1,6002024-11-05 MEDIUM 6.7 CVE-2024-33031 Memory corruption while processing the update SIM PB records request. Wcn3660b Firmware Patch available Fix from $1,6002024-11-04 MEDIUM 6.7 CVE-2024-23386 memory corruption when WiFi display APIs are invoked with large random inputs. Wsa8835 Firmware Patch available Fix from $1,6002024-11-04 HIGH 7.5 CVE-2024-33700 The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to caus… Wbr 6012 Firmware No fix yet Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-22065 There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authent… Mf258k Pro Firmware Mitigation only Fix from $1,9502024-10-29 HIGH 7.5 CVE-2024-45802EPSS 48% Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource Durin… Squid 6.10+ Fix from $1,9502024-10-28 HIGH 7.8 CVE-2024-0127 NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest O… Mitigation only Fix from $1,9502024-10-26 HIGH 8.2 CVE-2024-0126 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successfu… Mitigation only Fix from $1,9502024-10-26 CRITICAL 9.1 CVE-2024-49753 Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in … Zitadel 2.58.7 / 2.59.5+ Fix from $2,3002024-10-25 HIGH 8.6 CVE-2024-20495 A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Softwar… Adaptive Security Appliance Software Mitigation only Fix from $1,9502024-10-23 MEDIUM 5.5 CVE-2024-20274 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center… Secure Firewall Management Center Mitigation only Fix from $1,6002024-10-23 CRITICAL 9.2 CVE-2024-48919 Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via Cursor's Terminal Cmd-K/Ctrl… Mitigation only Fix from $2,3002024-10-22 CRITICAL 9.8 CVE-2024-49368EPSS 27% Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the… Nginx Ui after 1.9.9-4 Fix from $2,3002024-10-21 HIGH 8.1 CVE-2024-49361 ACON is a widely-used library of tools for machine learning that focuses on adaptive correlation optimization. A potential vulnerability has been ide… Mitigation only Fix from $1,9502024-10-18 HIGH 8.1 CVE-2024-48918 RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prior to 1.1.0 contain a vulnerab… Patch available Fix from $1,9502024-10-16 HIGH 8.9 CVE-2024-9348 Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view. Mitigation only Fix from $1,9502024-10-16 HIGH 8.5 CVE-2024-45219 Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as … Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 CRITICAL 9.1 CVE-2024-48914EPSS 60% Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an a… Patch available Fix from $2,3002024-10-15 HIGH 7.5 CVE-2024-6207 CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP messa… Controllogix 5580 Firmware 33.017 / 34.014+ Fix from $1,9502024-10-14 CRITICAL 9.8 CVE-2024-8755 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product … Loadmaster 7.2.61.0+ Fix from $2,3002024-10-11 HIGH 7.6 CVE-2024-45117 Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lea… Commerce Mitigation only Fix from $1,9502024-10-10 CRITICAL 9.8 CVE-2024-47823 Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and … Livewire 2.12.7 / 3.5.2+ Fix from $2,3002024-10-08 HIGH 8.8 CVE-2024-43611 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $1,9502024-10-08 HIGH 8.8 CVE-2024-43592 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $1,9502024-10-08