Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.7 CVE-2024-38483 Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access coul… Latitude 5290 2 In 1 Firmware 1.26.0 / 1.32.8+ Fix from $1,6002024-08-14 HIGH 7.2 CVE-2024-37373 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.0 CVE-2024-38201 Azure Stack Hub Elevation of Privilege Vulnerability Azure Stack Hub 1.2311.1.22+ Fix from $1,9502024-08-13 HIGH 7.8 CVE-2024-38196EPSS 6% Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20751 / 10.0.14393.7259+ Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-38189 KEVEPSS 8% Microsoft Project Remote Code Execution Vulnerability 365 Apps 16.0.5461.1001+ Fix from $1,9502024-08-13 MEDIUM 5.5 CVE-2023-31366 Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service. Uprof 4.1.424 / 4.2.816+ Fix from $1,6002024-08-13 MEDIUM 5.8 CVE-2023-31339 Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bo… Trusted Firmware A 2.10.1 / 2023.2+ Fix from $1,6002024-08-13 HIGH 7.3 CVE-2022-23817 Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/wri… Mitigation only Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-41976 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-… Ruggedcom Rm1224 Lte\(4g\) Eu Firmware 8.1+ Fix from $1,9502024-08-13 CRITICAL 9.1 CVE-2024-41940 A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privilege… Sinec Nms 3.0+ Fix from $2,3002024-08-13 HIGH 8.1 CVE-2024-30188EPSS 6% File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional resource files. This issue affect… Dolphinscheduler 3.2.2+ Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-29831 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.2.2+ Fix from $1,9502024-08-12 MEDIUM 6.8 CVE-2023-24062 Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of t… Vynamic Security Suite 3.3.0sr12 / 4.0.0sr04+ Fix from $1,6002024-08-08 MEDIUM 6.1 CVE-2024-6254 The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to… Brizy 2.5.2+ Fix from $1,6002024-08-08 CRITICAL 9.8 CVE-2024-23483 An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connec… Client Connector 4.2+ Fix from $2,3002024-08-06 CRITICAL 9.3 CVE-2024-6915 JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation th… Mitigation only Fix from $2,3002024-08-05 HIGH 7.9 CVE-2024-21978 Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data… Epyc 7203 Firmware Mitigation only Fix from $1,9502024-08-05 HIGH 8.8 CVE-2024-40721 The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visit… Tcb Servisign 1.0.24.0318+ Fix from $1,9502024-08-02 CRITICAL 9.8 CVE-2024-38879 A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 … Omnivise T3000 Application Server Mitigation only Fix from $2,3002024-08-02 HIGH 8.8 CVE-2024-40720 The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visit… Tcb Servisign 1.0.24.0318+ Fix from $1,9502024-08-02 CRITICAL 9.8 CVE-2024-42458 server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369. Neatvnc 0.8.1+ Fix from $2,3002024-08-02 HIGH 7.8 CVE-2023-1577 A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code wit… Drivers Management 3.1.1307.1308+ Fix from $1,9502024-07-31 MEDIUM 5.5 CVE-2017-3772 A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot. Pcmanager 2.6.40.3154+ Fix from $1,6002024-07-31 HIGH 8.8 CVE-2024-6978 Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28. Cato Client 5.10.34+ Fix from $1,9502024-07-31 HIGH 8.8 CVE-2024-6973 Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34. Cato Client 5.10.34+ Fix from $1,9502024-07-31 HIGH 8.8 CVE-2024-7340 The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse … Patch available Fix from $1,9502024-07-31 HIGH 7.5 CVE-2024-39948 A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th… Nvr4104 4ks2\/l Firmware 4.003.0000000.1.r.240515+ Fix from $1,9502024-07-31 HIGH 7.5 CVE-2024-39949 A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th… Nvr4104 4ks2\/l Firmware 4.003.0000000.1.r.240515+ Fix from $1,9502024-07-31 CRITICAL 9.8 CVE-2024-39950 A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate… Nvr4104 4ks2\/l Firmware 4.003.0000000.1.r.240515+ Fix from $2,3002024-07-31 HIGH 7.5 CVE-2024-39944 A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the… Nvr4104 4ks2\/l Firmware 4.003.0000000.1.r.240515+ Fix from $1,9502024-07-31