Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2024-34009 Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCA… Moodle 4.3.4+ Fix from $1,9502024-05-31 HIGH 8.1 CVE-2024-5138 The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap.… Snapd 2.63.1+ Fix from $1,9502024-05-31 MEDIUM 6.2 CVE-2024-33996 Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did … Moodle 4.1.10 / 4.2.7+ Fix from $1,6002024-05-31 CRITICAL 9.8 CVE-2024-33999 The referrer URL used by MFA required additional sanitizing, rather than being used directly. Moodle 4.3.4+ Fix from $2,3002024-05-31 MEDIUM 5.5 CVE-2024-22338 IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. … Security Verify Access Oidc Provider after 23.03 Fix from $1,6002024-05-31 HIGH 7.5 CVE-2024-3584 qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoi… Qdrant 1.9.0+ Fix from $1,9502024-05-30 HIGH 7.5 CVE-2024-3657 A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of servi… No fix yet Fix from $1,9502024-05-28 MEDIUM 5.7 CVE-2024-2199 A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modi… Mitigation only Fix from $1,6002024-05-28 MEDIUM 5.5 CVE-2024-35384 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file. Mjs No fix yet Fix from $1,6002024-05-21 HIGH 7.2 CVE-2024-4287 In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application… Anythingllm 1.0.0+ Fix from $1,9502024-05-20 CRITICAL 9.0 CVE-2024-36053 In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connect… Mitigation only Fix from $2,3002024-05-19 HIGH 7.2 CVE-2021-22508 A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL … Mitigation only Fix from $1,9502024-05-17 MEDIUM 6.7 CVE-2024-22429 Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit t… Edge Gateway 5000 Firmware 1.18.0 / 1.24.0+ Fix from $1,6002024-05-17 HIGH 8.8 CVE-2024-22120EPSS 77% Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip"… Zabbix 6.0.28 / 6.4.13+ Fix from $1,9502024-05-17 CRITICAL 10.0 CVE-2024-22476EPSS 36% Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable es… Mitigation only Fix from $2,3002024-05-16 HIGH 7.5 CVE-2024-23487 Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged use… Mitigation only Fix from $1,9502024-05-16 HIGH 7.5 CVE-2024-24981 Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to en… Mitigation only Fix from $1,9502024-05-16 MEDIUM 6.5 CVE-2024-22015 Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to potentially denial of service… Mitigation only Fix from $1,6002024-05-16 HIGH 7.2 CVE-2024-22095 Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged u… Mitigation only Fix from $1,9502024-05-16 HIGH 7.5 CVE-2024-22382 Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to ena… Mitigation only Fix from $1,9502024-05-16 MEDIUM 5.5 CVE-2023-48368 Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via loc… Media Sdk Mitigation only Fix from $1,6002024-05-16 MEDIUM 6.7 CVE-2023-47855 Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalat… Tdx Module 1.5.05.46.698+ Fix from $1,6002024-05-16 HIGH 8.2 CVE-2023-45745 Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalat… Tdx Module 1.5.05.46.698+ Fix from $1,9502024-05-16 HIGH 8.2 CVE-2023-38654 Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to … Mitigation only Fix from $1,9502024-05-16 HIGH 7.2 CVE-2023-28402 Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local ac… Mitigation only Fix from $1,9502024-05-16 MEDIUM 5.8 CVE-2023-22662 Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potenti… Mitigation only Fix from $1,6002024-05-16 CRITICAL 9.8 CVE-2024-4609 A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta… Factorytalk View 11.0+ Fix from $2,3002024-05-16 HIGH 7.5 CVE-2024-4321 A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading … Chuanhuchatgpt No fix yet Fix from $1,9502024-05-16 MEDIUM 5.5 CVE-2024-20394 A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condi… Appdynamics 24.4.0+ Fix from $1,6002024-05-15 HIGH 7.1 CVE-2024-25743 In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signa… Mitigation only Fix from $1,9502024-05-15