Vulnerabilities (CVE)

Filtered by CWE-20
Total 11158 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46946 2024-09-20 N/A 9.8 CRITICAL
langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9babcbeb9ff527b0ec0c6 (2023-10-05).
CVE-2024-6077 1 Rockwellautomation 14 1756-en4, 1756-en4 Firmware, Compact Guardlogix 5380 Sil 2 and 11 more 2024-09-19 N/A 7.5 HIGH
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.
CVE-2024-6258 1 Zephyrproject 1 Zephyr 2024-09-19 N/A 6.8 MEDIUM
BT: Missing length checks of net_buf in rfcomm_handle_data
CVE-2024-5931 1 Zephyrproject 1 Zephyr 2024-09-19 N/A 6.3 MEDIUM
BT: Unchecked user input in bap_broadcast_assistant
CVE-2024-6259 1 Zephyrproject 1 Zephyr 2024-09-19 N/A 7.6 HIGH
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
CVE-2024-6137 1 Zephyrproject 1 Zephyr 2024-09-19 N/A 7.6 HIGH
BT: Classic: SDP OOB access in get_att_search_list
CVE-2024-38483 1 Dell 82 Embedded Box Pc 5000, Embedded Box Pc 5000 Firmware, Latitude 12 Rugged Extreme 7214 and 79 more 2024-09-18 N/A 5.8 MEDIUM
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CVE-2024-38046 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2024-09-18 N/A 7.8 HIGH
PowerShell Elevation of Privilege Vulnerability
CVE-2024-44094 1 Google 1 Android 2024-09-18 N/A 7.8 HIGH
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-38194 1 Microsoft 1 Azure Web Apps 2024-09-17 N/A 8.4 HIGH
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
CVE-2024-38216 1 Microsoft 1 Azure Stack Hub 2024-09-17 N/A 8.2 HIGH
Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2024-38230 1 Microsoft 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more 2024-09-17 N/A 6.5 MEDIUM
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2024-38234 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2024-09-17 N/A 6.5 MEDIUM
Windows Networking Denial of Service Vulnerability
CVE-2024-38241 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2024-09-17 N/A 7.8 HIGH
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38243 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2024-09-17 N/A 7.8 HIGH
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38244 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2024-09-17 N/A 7.8 HIGH
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38245 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2024-09-17 N/A 7.8 HIGH
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38811 1 Vmware 1 Fusion 2024-09-17 N/A 8.8 HIGH
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
CVE-2024-21829 2024-09-16 N/A 7.5 HIGH
Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2024-21781 2024-09-16 N/A 7.2 HIGH
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.