Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Deck MEDIUM 6.5
CVE-2023-22470

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A databas…

Fix: 1.6.5 / 1.7.3+
Fix from $1,600 2023-01-14
Incopy HIGH 7.8
CVE-2023-21596

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrar…

Fix: after 17.4
Fix from $1,950 2023-01-13
Indesign HIGH 7.8
CVE-2023-21588

Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitra…

Fix: after 17.4
Fix from $1,950 2023-01-13
Gatsby MEDIUM 5.4
CVE-2023-22491

Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior t…

Fix: 5.25.1+
Fix from $1,600 2023-01-13
Ar7088h A Firmware HIGH 8.8
CVE-2022-46372

Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command executi…

Fix: after 16.10.3
Fix from $1,950 2023-01-12
Warp HIGH 8.0
CVE-2022-4428

support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching …

Fix: after 2022.10.106.0
Fix from $1,950 2023-01-11
Sugarcrm HIGH 8.8
CVE-2023-22952 KEVEPSS 80%

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Fix: 11.0.5 / 12.0.2+
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware MEDIUM 5.3
CVE-2023-20532

Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

Mitigation only
Fix from $1,600 2023-01-11
Romepi Firmware MEDIUM 6.1
CVE-2021-46767

Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a los…

Fix: 1.0.0.d / 1.0.0.6+
Fix from $1,600 2023-01-11
Milanpi Sp3 Firmware MEDIUM 5.3
CVE-2022-23814

Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential com…

Fix: 1.0.0.9+
Fix from $1,600 2023-01-11
Milanpi Firmware HIGH 7.5
CVE-2023-20522

Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.

Fix: 1.0.0.5 / 100d+
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware MEDIUM 6.5
CVE-2023-20525

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register po…

Mitigation only
Fix from $1,600 2023-01-11
Epyc 7h12 Firmware MEDIUM 6.5
CVE-2023-20527

Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial…

Mitigation only
Fix from $1,600 2023-01-11
Epyc 7003 Firmware HIGH 7.5
CVE-2023-20530

Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.

Mitigation only
Fix from $1,950 2023-01-11
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26404

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

Mitigation only
Fix from $1,600 2023-01-11
Epyc 7h12 Firmware HIGH 7.8
CVE-2021-26316

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in poten…

Mitigation only
Fix from $1,950 2023-01-11
Personnummer MEDIUM 5.3
CVE-2023-22963

The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expression.

Fix: 3.0.3+
Fix from $1,600 2023-01-11
Windows 10 HIGH 7.8
CVE-2023-21767

Windows Overlay Filter Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2023-01-10
Windows 10 1607 HIGH 7.8
CVE-2023-21749

Windows Kernel Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Windows 10 1809 MEDIUM 5.5
CVE-2023-21559

Windows Cryptographic Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Windows 10 1809 MEDIUM 5.5
CVE-2023-21550

Windows Cryptographic Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Windows 10 HIGH 7.8
CVE-2023-21558

Windows Error Reporting Service Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Windows 10 1809 MEDIUM 5.5
CVE-2023-21540

Windows Cryptographic Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Chrome MEDIUM 6.5
CVE-2023-0139

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass downlo…

Fix: 109.0.5414.74+
Fix from $1,600 2023-01-10
Pandora MEDIUM 6.5
CVE-2023-22898

workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive …

Fix: 1.3.1+
Fix from $1,600 2023-01-10
Qam8295p Firmware HIGH 7.8
CVE-2022-33300

Memory corruption in Automotive Android OS due to improper input validation.

No fix yet
Fix from $1,950 2023-01-09
Discourse MEDIUM 6.5
CVE-2022-23549

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Http4s MEDIUM 5.3
CVE-2023-22465

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-…

Fix: 0.21.34 / 0.22.15+
Fix from $1,600 2023-01-04
Dolphinscheduler CRITICAL 9.8
CVE-2022-45875

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects…

Fix: 3.0.2+
Fix from $2,300 2023-01-04
Go Ipld Prime HIGH 7.5
CVE-2023-22460

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…

Fix: 0.19.0+
Fix from $1,950 2023-01-04