Export limit exceeded: 365789 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365789 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2016-10394 | 1 Qualcomm | 10 Mdm9206, Mdm9206 Firmware, Mdm9607 and 7 more | 2025-01-09 | 9.8 Critical |
| Initial xbl_sec revision does not have all the debug policy features and critical checks. | ||||
| CVE-2017-11076 | 1 Qualcomm | 54 Msm8909w, Msm8909w Firmware, Msm8996au and 51 more | 2025-01-09 | 8.8 High |
| On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. | ||||
| CVE-2023-2749 | 1 Asustor | 2 Adm, Download Center | 2025-01-09 | 8.6 High |
| Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. Download Center on ADM 4.0 and above will be affected. Affected products and versions include: Download Center 1.1.5.r1280 and below. | ||||
| CVE-2017-15832 | 1 Qualcomm | 10 Mdm9206, Mdm9206 Firmware, Mdm9607 and 7 more | 2025-01-09 | 7.8 High |
| Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW | ||||
| CVE-2023-2909 | 1 Asustor | 1 Adm | 2025-01-09 | 8.5 High |
| EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below. | ||||
| CVE-2017-17772 | 1 Qualcomm | 14 Sd 450, Sd 450 Firmware, Sd 625 and 11 more | 2025-01-09 | 8.8 High |
| In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation. | ||||
| CVE-2023-34218 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 9.1 Critical |
| In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible | ||||
| CVE-2017-18153 | 1 Qualcomm | 10 9206 Lte Modem, 9206 Lte Modem Firmware, Apq8017 and 7 more | 2025-01-09 | 6.8 Medium |
| A race condition exists in a driver potentially leading to a use-after-free condition. | ||||
| CVE-2018-11922 | 1 Qualcomm | 44 215, 215 Firmware, Mdm9206 and 41 more | 2025-01-09 | 7.5 High |
| Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. | ||||
| CVE-2018-11952 | 1 Qualcomm | 46 Mdm9206, Mdm9206 Firmware, Mdm9607 and 43 more | 2025-01-09 | 7.8 High |
| An image with a version lower than the fuse version may potentially be booted lead to improper authentication. | ||||
| CVE-2023-25539 | 2 Dell, Linux | 2 Networker, Linux Kernel | 2025-01-09 | 8.4 High |
| Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity. | ||||
| CVE-2023-34219 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.3 Medium |
| In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API | ||||
| CVE-2023-34221 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.6 Medium |
| In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible | ||||
| CVE-2023-34222 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.6 Medium |
| In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible | ||||
| CVE-2023-34223 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.3 Medium |
| In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | ||||
| CVE-2023-34224 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.8 Medium |
| In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible | ||||
| CVE-2023-34225 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.6 Medium |
| In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible | ||||
| CVE-2023-34226 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 4.6 Medium |
| In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible | ||||
| CVE-2023-34227 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 5.3 Medium |
| In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks | ||||
| CVE-2023-34228 | 1 Jetbrains | 1 Teamcity | 2025-01-09 | 5.3 Medium |
| In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | ||||