Total
11158 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-28127 | 2025-02-12 | N/A | 7.5 HIGH | ||
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2024-25571 | 2025-02-12 | N/A | 2.3 LOW | ||
Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access. | |||||
CVE-2024-24582 | 2025-02-12 | N/A | 7.5 HIGH | ||
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2023-49615 | 2025-02-12 | N/A | 7.5 HIGH | ||
Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2023-43758 | 2025-02-12 | N/A | 8.2 HIGH | ||
Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2023-34440 | 2025-02-12 | N/A | 7.5 HIGH | ||
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2023-30450 | 1 Redpanda | 1 Redpanda | 2025-02-12 | N/A | 4.3 MEDIUM |
rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix was also backported to the 22.2 and 22.3 branches. | |||||
CVE-2024-2339 | 1 Dalibo | 1 Anonymizer | 2025-02-12 | N/A | 8.0 HIGH |
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the malicious code is executed and can grant escalated privileges to the malicious user. PostgreSQL Anonymizer v1.2 does provide a protection against this risk with the restrict_to_trusted_schemas option, but that protection is incomplete. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3. | |||||
CVE-2025-26358 | 2025-02-12 | N/A | 5.5 MEDIUM | ||
A CWE-20 "Improper Input Validation" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests. | |||||
CVE-2024-21971 | 2025-02-12 | N/A | 5.5 MEDIUM | ||
Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an operating system crash, potentially leading to denial of service. | |||||
CVE-2024-0112 | 2025-02-12 | N/A | 7.5 HIGH | ||
NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper input validation issue by escalating certain permissions to a limited degree. A successful exploit of this vulnerability might lead to code execution, denial of service, data corruption, information disclosure, or escalation of privilege. | |||||
CVE-2023-31345 | 2025-02-12 | N/A | 7.5 HIGH | ||
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | |||||
CVE-2023-31343 | 2025-02-11 | N/A | 7.5 HIGH | ||
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | |||||
CVE-2023-31342 | 2025-02-11 | N/A | 7.5 HIGH | ||
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | |||||
CVE-2024-21925 | 2025-02-11 | N/A | 8.2 HIGH | ||
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution. | |||||
CVE-2024-0179 | 2025-02-11 | N/A | 8.2 HIGH | ||
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution. | |||||
CVE-2025-21194 | 2025-02-11 | N/A | 7.1 HIGH | ||
Microsoft Surface Security Feature Bypass Vulnerability | |||||
CVE-2023-26070 | 1 Lexmark | 217 6500e, B2236, B2338 and 214 more | 2025-02-11 | N/A | 9.8 CRITICAL |
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4). | |||||
CVE-2023-26069 | 1 Lexmark | 152 B2236, B2338, B2442 and 149 more | 2025-02-11 | N/A | 9.8 CRITICAL |
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4). | |||||
CVE-2023-26067 | 1 Lexmark | 163 B2236, B2338, B2442 and 160 more | 2025-02-11 | N/A | 8.1 HIGH |
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). |