Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2022-33894 Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege… Xeon E 2314 Firmware Mitigation only Fix from $1,9502023-05-10 HIGH 7.8 CVE-2022-34147 Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC Performance Mini … Lapqc71a Firmware Mitigation only Fix from $1,9502023-05-10 MEDIUM 5.5 CVE-2022-25976 Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of ser… Virtual Raid On Cpu 7.7.6.1003+ Fix from $1,6002023-05-10 MEDIUM 6.7 CVE-2022-28699 Improper input validation for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local acc… Nuc8cchb Firmware Patch available Fix from $1,6002023-05-10 MEDIUM 6.0 CVE-2022-32577 Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable informa… Nuc5cpyh Firmware Patch available Fix from $1,6002023-05-10 HIGH 8.2 CVE-2023-1732 When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In… Circl 1.3.3+ Fix from $1,9502023-05-10 CRITICAL 9.1 CVE-2021-46754 Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloa… Ryzen 5300g Firmware Mitigation only Fix from $2,3002023-05-09 CRITICAL 9.1 CVE-2021-46756 Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or A… Epyc 72f3 Firmware Mitigation only Fix from $2,3002023-05-09 HIGH 8.8 CVE-2021-46773 Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code exe… Ryzen 6600h Firmware No fix yet Fix from $1,9502023-05-09 CRITICAL 9.1 CVE-2021-46762 Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service. Epyc 72f3 Firmware Mitigation only Fix from $2,3002023-05-09 HIGH 8.8 CVE-2021-46769 Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code e… Epyc 72f3 Firmware Mitigation only Fix from $1,9502023-05-09 MEDIUM 6.8 CVE-2021-46775 Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss o… Epyc 72f3 Firmware Mitigation only Fix from $1,6002023-05-09 HIGH 7.5 CVE-2022-23818 Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity. Epyc 72f3 Firmware Mitigation only Fix from $1,9502023-05-09 MEDIUM 6.5 CVE-2023-24950EPSS 67% Microsoft SharePoint Server Spoofing Vulnerability Sharepoint Enterprise Server Patch available Fix from $1,6002023-05-09 HIGH 7.5 CVE-2023-29335 Microsoft Word Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19926 / 10.0.14393.5921+ Fix from $1,9502023-05-09 MEDIUM 5.5 CVE-2023-28200 A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Mon… Ipados 11.7.5 / 12.6.4+ Fix from $1,6002023-05-08 MEDIUM 5.5 CVE-2023-27961 Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS … Ipados 9.4 / 11.7.5+ Fix from $1,6002023-05-08 CRITICAL 9.8 CVE-2023-31039 Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker tha… Brpc 1.5.0+ Fix from $2,3002023-05-08 CRITICAL 9.8 CVE-2023-31047 In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl… Django 3.2.19 / 4.1.9+ Fix from $2,3002023-05-07 MEDIUM 5.5 CVE-2023-30434 IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3… Elastic Storage System 6.1.2.6 / 6.1.6.1+ Fix from $1,6002023-05-05 MEDIUM 6.5 CVE-2022-43919 IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. … Mq Appliance 9.2.0.10 / 9.2.5.7+ Fix from $1,6002023-05-05 CRITICAL 9.8 CVE-2023-21494 Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attacker… Android Mitigation only Fix from $2,3002023-05-04 HIGH 7.8 CVE-2023-21498 Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite … Android Mitigation only Fix from $1,9502023-05-04 HIGH 7.8 CVE-2023-21501 Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code. Android Mitigation only Fix from $1,9502023-05-04 HIGH 7.8 CVE-2023-21502 Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation… Android Mitigation only Fix from $1,9502023-05-04 CRITICAL 9.8 CVE-2023-21503 Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to … Android Mitigation only Fix from $2,3002023-05-04 CRITICAL 9.8 CVE-2023-21504 Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause… Android Mitigation only Fix from $2,3002023-05-04 HIGH 7.3 CVE-2023-26125 Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially … Gin 1.9.0+ Fix from $1,9502023-05-04 CRITICAL 9.1 CVE-2022-46365 Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a … Streampark 2.0.0+ Fix from $2,3002023-05-01 HIGH 8.8 CVE-2023-0683 A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. Thinkagile Hx5530 Firmware 2.93_afbt30p / 3.72_tei388s+ Fix from $1,9502023-05-01