Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Dimension HIGH 7.8
CVE-2023-25881

Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution …

Fix: after 3.4.7
Fix from $1,950 2023-03-28
Gecko Software Development Kit MEDIUM 6.5
CVE-2023-0775

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection …

Mitigation only
Fix from $1,600 2023-03-28
Emui HIGH 7.5
CVE-2022-48356

The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed fac…

Mitigation only
Fix from $1,950 2023-03-27
Substance 3d Stager HIGH 7.8
CVE-2023-25865

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code…

Fix: after 2.0.0
Fix from $1,950 2023-03-27
Substance 3d Stager HIGH 7.8
CVE-2023-25867

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code…

Fix: after 2.0.0
Fix from $1,950 2023-03-27
Tensorflow MEDIUM 6.5
CVE-2023-25661

TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Fail…

Fix: 2.11.1+
Fix from $1,600 2023-03-27
Csaf Validator Lib MEDIUM 6.5
CVE-2022-47924

An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally installed Secvisogram in versions …

Fix: 0.1.0+
Fix from $1,600 2023-03-27
Csaf Validator Lib HIGH 7.5
CVE-2022-47925

The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient inp…

Fix: 0.1.0+
Fix from $1,950 2023-03-27
Android HIGH 7.3
CVE-2023-20976

In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to im…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 8.8
CVE-2023-20960

In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validat…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2022-20542

In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2023-03-24
Android MEDIUM 6.7
CVE-2022-42500

In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could lead to local escalation of pr…

Mitigation only
Fix from $1,600 2023-03-24
Openoffice HIGH 7.8
CVE-2022-47502

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. …

Fix: after 4.1.13
Fix from $1,950 2023-03-24
Moodle MEDIUM 6.5
CVE-2023-28330

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, manag…

Fix: 3.9.20 / 3.11.13+
Fix from $1,600 2023-03-23
Fedora MEDIUM 5.5
CVE-2023-1289

A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a rem…

Fix: 7.1.1-0+
Fix from $1,600 2023-03-23
Ios Xe HIGH 8.6
CVE-2023-20072

A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacke…

Mitigation only
Fix from $1,950 2023-03-23
Qradar Security Information And Event Manager HIGH 7.2
CVE-2022-43863

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities…

Fix: 7.4.3+
Fix from $1,950 2023-03-22
Illustrator HIGH 7.8
CVE-2023-25859

Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arb…

Fix: 27.3.1+
Fix from $1,950 2023-03-22
Custom Reports HIGH 8.8
CVE-2023-27984

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote cod…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Cairosvg HIGH 7.1
CVE-2023-27586

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing…

Fix: 2.7.0+
Fix from $1,950 2023-03-20
Otrs HIGH 7.8
CVE-2023-1250

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod…

Fix: 7.0.42 / 8.0.31+
Fix from $1,950 2023-03-20
Russh MEDIUM 5.9
CVE-2023-28113

russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is i…

Fix: 0.36.2+
Fix from $1,600 2023-03-16
Android MEDIUM 5.5
CVE-2023-21453

Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.

Mitigation only
Fix from $1,600 2023-03-16
Flatpak MEDIUM 6.5
CVE-2023-28100

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.…

Fix: 1.10.8 / 1.12.8+
Fix from $1,600 2023-03-16
Embedded Box Pc 3000 Firmware MEDIUM 6.7
CVE-2023-24571

Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with administrator privileges could potentially e…

Fix: 1.18.0+
Fix from $1,600 2023-03-16
Opensips HIGH 7.5
CVE-2023-28098

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, a specially crafted Authorization header ca…

Fix: 3.1.7 / 3.2.4+
Fix from $1,950 2023-03-15
Opensips HIGH 7.5
CVE-2023-28099

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, if `ds_is_in_list()` is used with an invali…

Fix: 3.1.9 / 3.2.6+
Fix from $1,950 2023-03-15
Opensips HIGH 7.5
CVE-2023-27600

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body …

Fix: 3.1.7 / 3.2.4+
Fix from $1,950 2023-03-15
Opensips HIGH 7.5
CVE-2023-27601

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body …

Fix: 3.1.7 / 3.2.4+
Fix from $1,950 2023-03-15
Opensips HIGH 7.5
CVE-2023-28095

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potential issue in `msg_translator.c:…

Fix: 3.1.7 / 3.2.4+
Fix from $1,950 2023-03-15