Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2023-39536
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of thi…
Aptio V
Mitigation only
HIGH 7.8
CVE-2023-39537
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network. A successful exploit of thi…
Aptio V
No fix yet
HIGH 7.8
CVE-2023-34470
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this …
Aptio V
Mitigation only
HIGH 8.8
CVE-2023-34330
AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A success…
Megarac Sp X
Mitigation only
HIGH 8.0
CVE-2023-34329
AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit o…
Megarac Sp X
Mitigation only
HIGH 8.8
CVE-2023-34473
AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability …
Megarac Sp X
Mitigation only
MEDIUM 6.5
CVE-2023-34472
AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in HTTP Headers. A successful ex…
Megarac Sp X
Mitigation only
CRITICAL 9.8
CVE-2023-34338
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successf…
Megarac Sp X
No fix yet
HIGH 8.8
CVE-2023-34337
AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC)…
Megarac Sp X
Mitigation only
HIGH 8.1
CVE-2023-34471
AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication cod…
Megarac Sp X
Mitigation only
CRITICAL 9.1
CVE-2023-34335
AMI BMC contains a vulnerability in the IPMI handler, where an
unauthenticated host is allowed to write to a host SPI flash, bypassing secure
boot pr…
Megarac Spx
12.7 / 13.5+
CRITICAL 9.1
CVE-2023-34342
AMI BMC contains a vulnerability in the IPMI handler, where an
attacker can upload and download arbitrary files under certain circumstances,
which ma…
Megarac Sp X
12.7 / 13.5+
HIGH 8.8
CVE-2023-34334
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can inject arbitrary shell commands,
which may l…
Megarac Sp X
12.7 / 13.5+
HIGH 8.8
CVE-2023-34336
AMI BMC contains a vulnerability in the IPMI handler, where an
attacker with the required privileges can cause a buffer overflow, which may
lead to c…
Megarac Sp X
12.7 / 13.5+
HIGH 8.8
CVE-2023-34343
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can inject arbitrary shell commands,
which may l…
Megarac Sp X
12.7 / 13.5+
HIGH 8.8
CVE-2023-34341
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can read and write to arbitrary locations
within…
Megarac Sp X
12.7 / 13.5+
MEDIUM 6.5
CVE-2023-34345
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can access arbitrary files, which may
lead to in…
Megarac Sp X
12.7 / 13.5+
MEDIUM 5.3
CVE-2023-34344
AMI BMC contains a vulnerability in the IPMI
handler, where an unauthorized attacker can use certain oracles to guess a
valid username, which may lea…
Megarac Sp X
12.7 / 13.5+
CRITICAL 9.1
CVE-2023-28863
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
Megarac Sp X
Mitigation only
HIGH 7.5
CVE-2023-25191
AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.
Megarac Sp X
Mitigation only
MEDIUM 5.3
CVE-2023-25192
AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.
Megarac Sp X
Mitigation only
MEDIUM 5.3
CVE-2022-40258
AMI Megarac Weak password hashes for
Redfish & API
Megarac Spx 12
5.00 / 7.00+
HIGH 8.8
CVE-2022-26872
AMI Megarac Password reset interception via API
Megarac Sp X
Mitigation only
CRITICAL 9.8
CVE-2022-40242
MegaRAC Default Credentials Vulnerability
Megarac Sp X
Mitigation only
CRITICAL 9.8
CVE-2022-40259
MegaRAC Default Credentials Vulnerability
Megarac Sp X
No fix yet
HIGH 7.5
CVE-2022-2827
AMI MegaRAC User Enumeration Vulnerability
Megarac Sp X
Mitigation only
HIGH 8.2
CVE-2022-40262
A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitiga…
Aptio V
No fix yet