Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2024-9802
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific info…
Zowe Api Mediation Layer
2.17.0+
MEDIUM 6.7
CVE-2024-20098
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2024-20099
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…
Yocto
Mitigation only
CRITICAL 9.8
CVE-2023-27584EPSS 34%
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…
Dragonfly
2.0.9+
MEDIUM 6.5
CVE-2024-45815
Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog b…
Backstage
1.26.0+
MEDIUM 6.5
CVE-2024-45816
Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access co…
Backstage
1.10.13+
MEDIUM 5.4
CVE-2024-46976
Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to in…
Backstage
1.10.13+
HIGH 7.5
CVE-2024-20089
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execut…
Yocto
Mitigation only
CRITICAL 9.8
CVE-2024-20080
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privileg…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2024-20081
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syst…
Yocto
Mitigation only
MEDIUM 5.5
CVE-2024-22261
SQL-Injection in Harbor allows priviledge users to leak the task IDs
Harbor
2.8.6 / 2.9.4+
MEDIUM 6.1
CVE-2024-22244
Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
Harbor
2.8.5 / 2.9.3+
HIGH 8.8
CVE-2024-5187
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due t…
Onnx
No fix yet
MEDIUM 5.3
CVE-2023-32871
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional ex…
Yocto
Mitigation only
HIGH 8.1
CVE-2023-52724
Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function.
Onos Kpimon
Patch available
HIGH 8.1
CVE-2023-52727
Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.
Onos Lib Go
No fix yet
MEDIUM 6.5
CVE-2023-52725
Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package.
Onos Kpimon
Patch available
MEDIUM 6.5
CVE-2023-52726
Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function imp…
Onos Ric Sdk Go
No fix yet
MEDIUM 5.5
CVE-2023-52728
Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.
Onos Lib Go
No fix yet
MEDIUM 5.3
CVE-2024-34043
O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.
Ric App Kpimon Go
No fix yet
MEDIUM 5.5
CVE-2024-31584
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
Pytorch
2.2.0+
HIGH 7.8
CVE-2024-31583
Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
Pytorch
2.2.0+
HIGH 8.4
CVE-2024-20053
In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System executi…
Yocto
Mitigation only
MEDIUM 6.6
CVE-2024-20054
In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System exec…
Yocto
Mitigation only
MEDIUM 6.3
CVE-2024-20055
In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System exec…
Yocto
Mitigation only
MEDIUM 6.0
CVE-2023-51699
Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection v…
Fluid
0.9.3+
HIGH 7.8
CVE-2024-21418
Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
Software For Open Networking In The Cloud
20181130.106 / 20191130.89+
MEDIUM 6.7
CVE-2024-20022
In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execut…
Yocto
Mitigation only
MEDIUM 6.7
CVE-2024-20023
In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution …
Yocto
Mitigation only
HIGH 7.5
CVE-2024-26150
`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backs…
Backstage Backend Common
0.19.10 / 0.20.2+