Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android MEDIUM 6.7
CVE-2023-20634

In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,600 2023-03-07
Software Collections HIGH 8.6
CVE-2022-4904

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbit…

Fix: 1.19.0+
Fix from $1,950 2023-03-06
Moodle MEDIUM 5.3
CVE-2021-36402

In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Kubernetes HIGH 8.8
CVE-2022-3294

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node ob…

Fix: 1.22.16 / 1.23.14+
Fix from $1,950 2023-03-01
HTTP Server HIGH 7.5
CVE-2023-26281

IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. I…

Patch available
Fix from $1,950 2023-03-01
Email Security Appliance HIGH 7.2
CVE-2023-20009

A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow…

Fix: 12.5.3-041 / 12.8.1-021+
Fix from $1,950 2023-03-01
Asyncos MEDIUM 5.3
CVE-2022-20952

A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA…

Fix: 14.0.4+
Fix from $1,600 2023-03-01
Mq For Hpe Nonstop HIGH 7.5
CVE-2022-40237

IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic. IBM X-Fo…

Patch available
Fix from $1,950 2023-02-27
Imcat CRITICAL 9.8
CVE-2021-35370

An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

No fix yet
Fix from $2,300 2023-02-24
Apache Airflow Providers Google CRITICAL 9.8
CVE-2023-25691

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $2,300 2023-02-24
Apache Airflow Providers Google HIGH 7.5
CVE-2023-25692

Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1…

Fix: 8.10.0+
Fix from $1,950 2023-02-24
Apache Airflow Providers Apache Sqoop CRITICAL 9.8
CVE-2023-25693

Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

Fix: 3.1.1+
Fix from $2,300 2023-02-24
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2023-25696

Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

Fix: 5.1.3+
Fix from $2,300 2023-02-24
Horizon MEDIUM 6.1
CVE-2023-0867

Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could all…

Fix: 31.0.4 / 2023.1.0+
Fix from $1,600 2023-02-23
Horizon MEDIUM 6.1
CVE-2023-0868

Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session …

Fix: 31.0.4 / 2023.1.0+
Fix from $1,600 2023-02-23
Horizon MEDIUM 6.1
CVE-2023-0869

Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session inform…

Fix: 31.0.4 / 2023.1.0+
Fix from $1,600 2023-02-23
Checkmk HIGH 7.5
CVE-2022-46303

Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana…

Mitigation only
Fix from $1,950 2023-02-20
Checkmk HIGH 8.8
CVE-2022-46836

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta…

No fix yet
Fix from $1,950 2023-02-20
Checkmk HIGH 7.8
CVE-2022-47909

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions o…

No fix yet
Fix from $1,950 2023-02-20
After Effects HIGH 7.8
CVE-2023-22239

After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbit…

Fix: 22.6.4 / 23.2.0+
Fix from $1,950 2023-02-17
Bridge HIGH 7.8
CVE-2023-22228

Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a…

Fix: 12.0.4 / 13.0.2+
Fix from $1,950 2023-02-17
Photoshop HIGH 7.8
CVE-2023-21574

Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary …

Fix: 23.5.4 / 24.1.1+
Fix from $1,950 2023-02-17
Framemaker HIGH 7.8
CVE-2023-21621

FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary …

Fix: after 2020.0.4
Fix from $1,950 2023-02-17
Db2 HIGH 7.5
CVE-2022-43929

IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-F…

Patch available
Fix from $1,950 2023-02-17
Python HIGH 7.5
CVE-2023-24329EPSS 20%

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with bl…

Fix: 3.7.17 / 3.8.17+
Fix from $1,950 2023-02-17
System Usage Report HIGH 7.8
CVE-2022-33190

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of pr…

Fix: 2.4.8902+
Fix from $1,950 2023-02-16
System Usage Report CRITICAL 9.8
CVE-2022-33964

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of …

Fix: 2.4.8902+
Fix from $2,300 2023-02-16
Openbmc MEDIUM 6.5
CVE-2022-29494

Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated us…

Mitigation only
Fix from $1,600 2023-02-16
Xeon Gold 5317 Firmware HIGH 7.0
CVE-2022-26837

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege…

Mitigation only
Fix from $1,950 2023-02-16
Undici HIGH 7.5
CVE-2023-24807

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expre…

Fix: 5.19.1+
Fix from $1,950 2023-02-16