Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-9802 The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific info… Zowe Api Mediation Layer 2.17.0+ Fix from $1,6002024-10-10 MEDIUM 6.7 CVE-2024-20098 In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi… Yocto Mitigation only Fix from $1,6002024-10-07 MEDIUM 6.7 CVE-2024-20099 In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi… Yocto Mitigation only Fix from $1,6002024-10-07 CRITICAL 9.8 CVE-2023-27584EPSS 34% Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a… Dragonfly 2.0.9+ Fix from $2,3002024-09-19 MEDIUM 6.5 CVE-2024-45815 Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog b… Backstage 1.26.0+ Fix from $1,6002024-09-17 MEDIUM 6.5 CVE-2024-45816 Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access co… Backstage 1.10.13+ Fix from $1,6002024-09-17 MEDIUM 5.4 CVE-2024-46976 Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to in… Backstage 1.10.13+ Fix from $1,6002024-09-17 HIGH 7.5 CVE-2024-20089 In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execut… Yocto Mitigation only Fix from $1,9502024-09-02 CRITICAL 9.8 CVE-2024-20080 In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privileg… Yocto Mitigation only Fix from $2,3002024-07-01 MEDIUM 6.7 CVE-2024-20081 In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syst… Yocto Mitigation only Fix from $1,6002024-07-01 MEDIUM 5.5 CVE-2024-22261 SQL-Injection in Harbor allows priviledge users to leak the task IDs Harbor 2.8.6 / 2.9.4+ Fix from $1,6002024-06-11 MEDIUM 6.1 CVE-2024-22244 Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site. Harbor 2.8.5 / 2.9.3+ Fix from $1,6002024-06-10 HIGH 8.8 CVE-2024-5187 A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due t… Onnx No fix yet Fix from $1,9502024-06-06 MEDIUM 5.3 CVE-2023-32871 In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional ex… Yocto Mitigation only Fix from $1,6002024-05-06 HIGH 8.1 CVE-2023-52724 Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function. Onos Kpimon Patch available Fix from $1,9502024-04-30 HIGH 8.1 CVE-2023-52727 Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits. Onos Lib Go No fix yet Fix from $1,9502024-04-30 MEDIUM 6.5 CVE-2023-52725 Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package. Onos Kpimon Patch available Fix from $1,6002024-04-30 MEDIUM 6.5 CVE-2023-52726 Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function imp… Onos Ric Sdk Go No fix yet Fix from $1,6002024-04-30 MEDIUM 5.5 CVE-2023-52728 Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString. Onos Lib Go No fix yet Fix from $1,6002024-04-30 MEDIUM 5.3 CVE-2024-34043 O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message. Ric App Kpimon Go No fix yet Fix from $1,6002024-04-30 MEDIUM 5.5 CVE-2024-31584 Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. Pytorch 2.2.0+ Fix from $1,6002024-04-19 HIGH 7.8 CVE-2024-31583 Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp. Pytorch 2.2.0+ Fix from $1,9502024-04-17 HIGH 8.4 CVE-2024-20053 In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System executi… Yocto Mitigation only Fix from $1,9502024-04-01 MEDIUM 6.6 CVE-2024-20054 In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System exec… Yocto Mitigation only Fix from $1,6002024-04-01 MEDIUM 6.3 CVE-2024-20055 In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System exec… Yocto Mitigation only Fix from $1,6002024-04-01 MEDIUM 6.0 CVE-2023-51699 Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection v… Fluid 0.9.3+ Fix from $1,6002024-03-15 HIGH 7.8 CVE-2024-21418 Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability Software For Open Networking In The Cloud 20181130.106 / 20191130.89+ Fix from $1,9502024-03-12 MEDIUM 6.7 CVE-2024-20022 In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execut… Yocto Mitigation only Fix from $1,6002024-03-04 MEDIUM 6.7 CVE-2024-20023 In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution … Yocto Mitigation only Fix from $1,6002024-03-04 HIGH 7.5 CVE-2024-26150 `@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backs… Backstage Backend Common 0.19.10 / 0.20.2+ Fix from $1,9502024-02-23