Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android MEDIUM 6.7
CVE-2022-32652

In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privilege…

Mitigation only
Fix from $1,600 2023-01-03
Android MEDIUM 6.7
CVE-2022-32653

In mtk-aie, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privilege…

Mitigation only
Fix from $1,600 2023-01-03
Kenny2automate MEDIUM 6.5
CVE-2023-22452

kenny2automate is a Discord bot. In the web interface for server settings, form elements were generated with Discord channel IDs as part of input nam…

Patch available
Fix from $1,600 2023-01-02
Jetson Linux HIGH 7.9
CVE-2022-42269

NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local atta…

Fix: 32.7.2+
Fix from $1,950 2022-12-30
Virtual Gpu MEDIUM 5.5
CVE-2022-34681

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a …

Fix: 11.11 / 13.6+
Fix from $1,600 2022-12-30
Aslan Al10 Firmware HIGH 7.5
CVE-2022-39012

Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnor…

Fix: after 11.1.0.10118
Fix from $1,950 2022-12-28
Nosurf HIGH 7.5
CVE-2020-36564

Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied to…

Fix: 1.1.1+
Fix from $1,950 2022-12-27
Vios MEDIUM 6.2
CVE-2022-43848

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause …

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-43849

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a de…

Patch available
Fix from $1,600 2022-12-23
Vios MEDIUM 6.2
CVE-2022-40233

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a …

Patch available
Fix from $1,600 2022-12-23
Wheel HIGH 7.5
CVE-2022-40898

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker c…

Fix: 0.38.1+
Fix from $1,950 2022-12-23
Junos HIGH 7.5
CVE-2022-22184

An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthent…

Mitigation only
Fix from $1,950 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-34476

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability af…

Fix: 102.0+
Fix from $2,300 2022-12-22
Bigfix Insights For Vulnerability Remediation MEDIUM 6.5
CVE-2022-44756

Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires pri…

Fix: after 2.0
Fix from $1,600 2022-12-21
Karaf CRITICAL 9.8
CVE-2022-40145

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function …

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-12-21
Harmonyos HIGH 7.5
CVE-2022-46328

Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

Fix: 2.1+
Fix from $1,950 2022-12-20
Financial Transaction Manager MEDIUM 5.5
CVE-2022-43875

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations,…

Patch available
Fix from $1,600 2022-12-20
Lite Server HIGH 7.5
CVE-2022-25940

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters …

No fix yet
Fix from $1,950 2022-12-20
Bm78 Firmware MEDIUM 5.4
CVE-2022-46401

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is…

No fix yet
Fix from $1,600 2022-12-19
Compactlogix 5480 Firmware HIGH 7.5
CVE-2022-3752

An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-servic…

Mitigation only
Fix from $1,950 2022-12-19
Otrs CRITICAL 9.8
CVE-2022-4427

Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This iss…

Fix: 7.0.40 / 8.0.28+
Fix from $2,300 2022-12-19
Paydroid HIGH 7.8
CVE-2022-26582

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. …

Mitigation only
Fix from $1,950 2022-12-16
Compactlogix 5370 Firmware HIGH 7.5
CVE-2022-3157

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a…

Fix: after 33
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-42534

In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible privilege escalation due to improper input validation. This could lead to local…

Mitigation only
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20584

In page_number of shared_mem.c, there is a possible code execution in secure world due to improper input validation. This could lead to local escalat…

Mitigation only
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20585

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local esc…

Mitigation only
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20586

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local esc…

Mitigation only
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20587

In ppmp_validate_wsm of drm_fw.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2022-12-16
Android MEDIUM 5.5
CVE-2022-20590

In valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lead to lo…

Mitigation only
Fix from $1,600 2022-12-16
Android MEDIUM 5.5
CVE-2022-20592

In ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local informatio…

Mitigation only
Fix from $1,600 2022-12-16