Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Odbc HIGH 7.8
CVE-2023-23375

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

Fix: 17.10.3.1 / 18.2.1.1+
Fix from $1,950 2023-04-11
Windows 10 1607 CRITICAL 9.8
CVE-2023-21554EPSS 95%

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Fix: 10.0.14393.5850 / 10.0.17763.4252+
Fix from $2,300 2023-04-11
Fortianalyzer MEDIUM 5.5
CVE-2022-42477

An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an …

Fix: 7.0.7+
Fix from $1,600 2023-04-11
Tia Portal HIGH 7.3
CVE-2023-26293

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TI…

Patch available
Fix from $1,950 2023-04-11
Cxtpc Firmware HIGH 8.1
CVE-2023-26067EPSS 38%

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

No fix yet
Fix from $1,950 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26068EPSS 12%

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26069

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26070

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

No fix yet
Fix from $2,300 2023-04-10
Apache Airflow Providers Apache Drill HIGH 7.5
CVE-2023-28707

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider:…

Fix: 2.3.2+
Fix from $1,950 2023-04-07
Apache Airflow Providers Apache Spark HIGH 7.5
CVE-2023-28710

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider:…

Fix: 4.0.1+
Fix from $1,950 2023-04-07
Secure Network Analytics HIGH 7.2
CVE-2023-20103

A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affect…

Fix: 7.4.2+
Fix from $1,950 2023-04-05
Webex Meetings MEDIUM 5.4
CVE-2023-20132

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site sc…

Mitigation only
Fix from $1,600 2023-04-05
Webex Meetings MEDIUM 6.5
CVE-2023-20134

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site sc…

Mitigation only
Fix from $1,600 2023-04-05
Envoy CRITICAL 9.1
CVE-2023-27493

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy HIGH 7.5
CVE-2023-27496

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $1,950 2023-04-04
Envoy CRITICAL 9.1
CVE-2023-27491

Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines…

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy CRITICAL 9.8
CVE-2023-27488

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy CRITICAL 9.1
CVE-2023-27487

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Firefly Iii CRITICAL 9.8
CVE-2023-1789

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.

Fix: 5.7.18+
Fix from $2,300 2023-04-01
Cs141 Firmware HIGH 7.5
CVE-2022-47188

There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could u…

Fix: 2.06+
Fix from $1,950 2023-03-31
Cs141 Firmware CRITICAL 9.1
CVE-2022-47189

Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration, in order to disrupt the norm…

Fix: 2.06+
Fix from $2,300 2023-03-31
Cs141 Firmware CRITICAL 9.8
CVE-2022-47190

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute a…

Fix: 2.06+
Fix from $2,300 2023-03-31
Cs141 Firmware HIGH 8.8
CVE-2022-47191

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing h…

Fix: 2.06+
Fix from $1,950 2023-03-31
Cs141 Firmware HIGH 8.8
CVE-2022-47192

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of t…

Fix: 2.06+
Fix from $1,950 2023-03-31
Acymailing CRITICAL 9.8
CVE-2023-28731

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office…

Fix: 8.3.0+
Fix from $2,300 2023-03-30
Acymailing HIGH 7.5
CVE-2023-28732

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access…

Fix: 8.3.0+
Fix from $1,950 2023-03-30
Acymailing MEDIUM 6.1
CVE-2023-28733

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication…

Fix: 8.3.0+
Fix from $1,600 2023-03-30
Irfanview HIGH 7.8
CVE-2023-24304

Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.

Mitigation only
Fix from $1,950 2023-03-28
Dimension HIGH 7.8
CVE-2023-25901

Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution …

Fix: after 3.4.7
Fix from $1,950 2023-03-28
Dimension HIGH 7.8
CVE-2023-25879

Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution …

Fix: after 3.4.7
Fix from $1,950 2023-03-28