Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.3 CVE-2023-46047 An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is d… Sane Backends No fix yet Fix from $1,9502024-03-27 HIGH 7.8 CVE-2024-23482 The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.2… Client Connector 4.2.0.241+ Fix from $1,9502024-03-26 HIGH 7.5 CVE-2024-2425 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the … Powerflex 527 Ac Drives Firmware No fix yet Fix from $1,9502024-03-25 HIGH 7.5 CVE-2024-2426 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di… Powerflex 527 Ac Drives Firmware Mitigation only Fix from $1,9502024-03-25 HIGH 7.5 CVE-2024-2427 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data… Powerflex 527 Ac Drives Firmware Mitigation only Fix from $1,9502024-03-25 MEDIUM 5.3 CVE-2024-29042 Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker contr… Translate 3.0.0+ Fix from $1,6002024-03-22 HIGH 8.2 CVE-2024-27918 Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in … Coder 2.6.1 / 2.7.3+ Fix from $1,9502024-03-21 HIGH 7.2 CVE-2024-2443 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.17 / 3.9.12+ Fix from $1,9502024-03-20 HIGH 7.2 CVE-2024-2469 An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected … Enterprise Server 3.8.17 / 3.9.12+ Fix from $1,9502024-03-20 MEDIUM 5.3 CVE-2023-45177 IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM… Mq 9.0.0.21 / 9.1.0.18+ Fix from $1,6002024-03-20 MEDIUM 6.0 CVE-2024-23634 GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerabi… Geoserver 2.23.5 / 2.24.2+ Fix from $1,6002024-03-20 HIGH 7.2 CVE-2023-51444 GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerabili… Geoserver 2.23.4+ Fix from $1,9502024-03-20 MEDIUM 6.5 CVE-2024-24683 Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to… Hop Engine 2.8.0+ Fix from $1,6002024-03-19 MEDIUM 6.8 CVE-2024-25942 Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potent… Poweredge R730 Firmware 2.14.0 / 2.19.0+ Fix from $1,6002024-03-19 MEDIUM 6.1 CVE-2024-28855 ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` inste… Zitadel 2.41.15 / 2.42.15+ Fix from $1,6002024-03-18 MEDIUM 5.9 CVE-2024-25656 Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipm… Mitigation only Fix from $1,6002024-03-18 CRITICAL 9.8 CVE-2023-7248 Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.  The vulnerability would affect one of V… Vertica 11.1.1-25 / 12.0.4-19+ Fix from $2,3002024-03-15 HIGH 7.5 CVE-2023-7060 Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the desti… Zephyr 3.6.0+ Fix from $1,9502024-03-15 MEDIUM 6.7 CVE-2023-32633 Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable esc… Mitigation only Fix from $1,6002024-03-14 HIGH 7.4 CVE-2024-20327 A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers … Ios Xr 7.9.21 / 7.10.1+ Fix from $1,9502024-03-13 HIGH 7.4 CVE-2024-20318 A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card ne… Mitigation only Fix from $1,9502024-03-13 HIGH 7.5 CVE-2024-24549EPSS 23% Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the requ… Tomcat 8.5.99 / 9.0.86+ Fix from $1,9502024-03-13 MEDIUM 5.4 CVE-2024-1854 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Essential Blocks 4.5.2+ Fix from $1,6002024-03-13 HIGH 8.4 CVE-2024-0161 Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileg… Poweredge T360 Firmware 1.1.1 / 1.13.2+ Fix from $1,9502024-03-13 CRITICAL 9.9 CVE-2024-27135EPSS 6% Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function w… Pulsar 2.10.6 / 2.11.4+ Fix from $2,3002024-03-12 HIGH 8.8 CVE-2024-27894 The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referen… Pulsar 2.10.6 / 2.11.4+ Fix from $1,9502024-03-12 MEDIUM 6.5 CVE-2024-26197 Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Server 2012 10.0.14393.6796 / 10.0.17763.5576+ Fix from $1,6002024-03-12 MEDIUM 5.5 CVE-2024-26181 Windows Kernel Denial of Service Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,6002024-03-12 HIGH 7.8 CVE-2024-26170EPSS 7% Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.4170 / 10.0.19045.4170+ Fix from $1,9502024-03-12 HIGH 7.8 CVE-2024-26173 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,9502024-03-12