Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zowe Api Mediation Layer MEDIUM 5.3
CVE-2024-9802

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific info…

Fix: 2.17.0+
Fix from $1,600 2024-10-10
Yocto MEDIUM 6.7
CVE-2024-20098

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2024-10-07
Yocto MEDIUM 6.7
CVE-2024-20099

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2024-10-07
Dragonfly CRITICAL 9.8
CVE-2023-27584EPSS 34%

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…

Fix: 2.0.9+
Fix from $2,300 2024-09-19
Backstage MEDIUM 6.5
CVE-2024-45815

Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog b…

Fix: 1.26.0+
Fix from $1,600 2024-09-17
Backstage MEDIUM 6.5
CVE-2024-45816

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access co…

Fix: 1.10.13+
Fix from $1,600 2024-09-17
Backstage MEDIUM 5.4
CVE-2024-46976

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to in…

Fix: 1.10.13+
Fix from $1,600 2024-09-17
Yocto HIGH 7.5
CVE-2024-20089

In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2024-09-02
Yocto CRITICAL 9.8
CVE-2024-20080

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privileg…

Mitigation only
Fix from $2,300 2024-07-01
Yocto MEDIUM 6.7
CVE-2024-20081

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syst…

Mitigation only
Fix from $1,600 2024-07-01
Harbor MEDIUM 5.5
CVE-2024-22261

SQL-Injection in Harbor allows priviledge users to leak the task IDs

Fix: 2.8.6 / 2.9.4+
Fix from $1,600 2024-06-11
Harbor MEDIUM 6.1
CVE-2024-22244

Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

Fix: 2.8.5 / 2.9.3+
Fix from $1,600 2024-06-10
Onnx HIGH 8.8
CVE-2024-5187

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due t…

No fix yet
Fix from $1,950 2024-06-06
Yocto MEDIUM 5.3
CVE-2023-32871

In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional ex…

Mitigation only
Fix from $1,600 2024-05-06
Onos Kpimon HIGH 8.1
CVE-2023-52724

Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function.

Patch available
Fix from $1,950 2024-04-30
Onos Lib Go HIGH 8.1
CVE-2023-52727

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.

No fix yet
Fix from $1,950 2024-04-30
Onos Kpimon MEDIUM 6.5
CVE-2023-52725

Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package.

Patch available
Fix from $1,600 2024-04-30
Onos Ric Sdk Go MEDIUM 6.5
CVE-2023-52726

Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function imp…

No fix yet
Fix from $1,600 2024-04-30
Onos Lib Go MEDIUM 5.5
CVE-2023-52728

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.

No fix yet
Fix from $1,600 2024-04-30
Ric App Kpimon Go MEDIUM 5.3
CVE-2024-34043

O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.

No fix yet
Fix from $1,600 2024-04-30
Pytorch MEDIUM 5.5
CVE-2024-31584

Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

Fix: 2.2.0+
Fix from $1,600 2024-04-19
Pytorch HIGH 7.8
CVE-2024-31583

Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.

Fix: 2.2.0+
Fix from $1,950 2024-04-17
Yocto HIGH 8.4
CVE-2024-20053

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,950 2024-04-01
Yocto MEDIUM 6.6
CVE-2024-20054

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System exec…

Mitigation only
Fix from $1,600 2024-04-01
Yocto MEDIUM 6.3
CVE-2024-20055

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System exec…

Mitigation only
Fix from $1,600 2024-04-01
Fluid MEDIUM 6.0
CVE-2023-51699

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection v…

Fix: 0.9.3+
Fix from $1,600 2024-03-15
Software For Open Networking In The Cloud HIGH 7.8
CVE-2024-21418

Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

Fix: 20181130.106 / 20191130.89+
Fix from $1,950 2024-03-12
Yocto MEDIUM 6.7
CVE-2024-20022

In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execut…

Mitigation only
Fix from $1,600 2024-03-04
Yocto MEDIUM 6.7
CVE-2024-20023

In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution …

Mitigation only
Fix from $1,600 2024-03-04
Backstage Backend Common HIGH 7.5
CVE-2024-26150

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backs…

Fix: 0.19.10 / 0.20.2+
Fix from $1,950 2024-02-23