Search Results (40562 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-7331 1 Totolink 2 A3300r, A3300r Firmware 2024-08-01 8.8 High
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-41950 1 Deepset 1 Haystack 2024-08-01 7.5 High
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone can create and render that template on the client machine they run any code. The vulnerability has been fixed with Haystack `2.3.1`.
CVE-2024-41660 1 Openbmc-project 1 Slpd-lite 2024-08-01 9.8 Critical
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the slpd-lite daemon on the BMC. Patches will be available in the latest openbmc/slpd-lite repository.
CVE-2024-40946 2024-07-15 4.7 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-48737 2024-07-05 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-48736 2024-07-05 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-47581 2024-06-20 3.3 Low
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-36699 2024-06-14 0.0 Low
DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2023-52756 1 Redhat 2 Enterprise Linux, Rhel Eus 2024-06-08 4.4 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-21506 2024-06-05 5.2 Medium
Duplicate of CVE-2024-5629.
CVE-2023-52734 1 Redhat 1 Enterprise Linux 2024-05-28 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52758 1 Redhat 1 Enterprise Linux 2024-05-24 4.4 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52793 2024-05-24 4.4 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-47326 2024-05-23 5.3 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52630 2024-04-30 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-26613 2024-03-12 3.3 Low
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52466 1 Redhat 1 Enterprise Linux 2024-03-03 4.4 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-20577 2024-02-13 7.4 High
A vulnerability was found in AMD hardware due to a heap overflow in the SMM module. This issue could allow a local unauthenticated attacker to enable writing to SPI flash to execute arbitrary code.
CVE-2023-5129 1 Redhat 5 Enterprise Linux, Rhel Aus, Rhel E4s and 2 more 2023-11-07 0.0 Low
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863.
CVE-2023-39195 2023-11-07 0.0 Low
CVE-2023-39195 was found to be a duplicate of CVE-2023-42755. Please see https://access.redhat.com/security/cve/CVE-2023-42755 for more information.