Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-34009
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCA…
Moodle
4.3.4+
HIGH 8.1
CVE-2024-5138
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap.…
Snapd
2.63.1+
MEDIUM 6.2
CVE-2024-33996
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did …
Moodle
4.1.10 / 4.2.7+
CRITICAL 9.8
CVE-2024-33999
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
Moodle
4.3.4+
MEDIUM 5.5
CVE-2024-22338
IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. …
Security Verify Access Oidc Provider
after 23.03
HIGH 7.5
CVE-2024-3584
qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoi…
Qdrant
1.9.0+
HIGH 7.5
CVE-2024-3657
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of servi…
No fix yet
MEDIUM 5.7
CVE-2024-2199
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modi…
Mitigation only
MEDIUM 5.5
CVE-2024-35384
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.
Mjs
No fix yet
HIGH 7.2
CVE-2024-4287
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application…
Anythingllm
1.0.0+
CRITICAL 9.0
CVE-2024-36053
In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connect…
Mitigation only
HIGH 7.2
CVE-2021-22508
A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL …
Mitigation only
MEDIUM 6.7
CVE-2024-22429
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit t…
Edge Gateway 5000 Firmware
1.18.0 / 1.24.0+
HIGH 8.8
CVE-2024-22120EPSS 77%
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip"…
Zabbix
6.0.28 / 6.4.13+
CRITICAL 10.0
CVE-2024-22476EPSS 36%
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable es…
Mitigation only
HIGH 7.5
CVE-2024-23487
Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged use…
Mitigation only
HIGH 7.5
CVE-2024-24981
Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to en…
Mitigation only
MEDIUM 6.5
CVE-2024-22015
Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to potentially denial of service…
Mitigation only
HIGH 7.2
CVE-2024-22095
Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged u…
Mitigation only
HIGH 7.5
CVE-2024-22382
Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to ena…
Mitigation only
MEDIUM 5.5
CVE-2023-48368
Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via loc…
Media Sdk
Mitigation only
MEDIUM 6.7
CVE-2023-47855
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalat…
Tdx Module
1.5.05.46.698+
HIGH 8.2
CVE-2023-45745
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalat…
Tdx Module
1.5.05.46.698+
HIGH 8.2
CVE-2023-38654
Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to …
Mitigation only
HIGH 7.2
CVE-2023-28402
Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local ac…
Mitigation only
MEDIUM 5.8
CVE-2023-22662
Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potenti…
Mitigation only
CRITICAL 9.8
CVE-2024-4609
A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…
Factorytalk View
11.0+
HIGH 7.5
CVE-2024-4321
A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading …
Chuanhuchatgpt
No fix yet
MEDIUM 5.5
CVE-2024-20394
A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condi…
Appdynamics
24.4.0+
HIGH 7.1
CVE-2024-25743
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signa…
Mitigation only