Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.5
CVE-2022-20545

In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to re…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20507

In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. Thi…

Patch available
Fix from $1,950 2022-12-16
Android HIGH 7.8
CVE-2022-20512

In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This cou…

Mitigation only
Fix from $1,950 2022-12-16
Zeppelin MEDIUM 6.5
CVE-2021-28655

The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. …

Fix: after 0.9.0
Fix from $1,600 2022-12-16
Ipados HIGH 7.8
CVE-2022-46701

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a …

Fix: 13.1 / 16.2+
Fix from $1,950 2022-12-15
Ipados CRITICAL 9.8
CVE-2022-42837

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, ma…

Fix: 9.2 / 15.7.2+
Fix from $2,300 2022-12-15
Web Service Report Generation MEDIUM 5.9
CVE-2022-46768EPSS 48%

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper v…

Fix: 6.0.12 / 6.2.6+
Fix from $1,600 2022-12-15
Openemr HIGH 7.5
CVE-2022-4504

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,950 2022-12-15
Sicam Pas\/pqs HIGH 7.5
CVE-2022-43723

A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not p…

Fix: 8.06+
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20470

In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation…

Mitigation only
Fix from $1,950 2022-12-13
Simatic S7 Plcsim Advanced Firmware HIGH 7.5
CVE-2021-40365

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of ser…

Fix: 4.6.0 / 5.0+
Fix from $1,950 2022-12-13
Simatic S7 Plcsim Advanced Firmware MEDIUM 5.5
CVE-2021-44694

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of ser…

Fix: 4.6.0 / 5.0+
Fix from $1,600 2022-12-13
Atlant HIGH 7.5
CVE-2022-45871

A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsi…

Mitigation only
Fix from $1,950 2022-12-13
Cxf HIGH 7.5
CVE-2022-46363

A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vul…

Fix: 3.4.10 / 3.5.5+
Fix from $1,950 2022-12-13
Movable Type MEDIUM 6.5
CVE-2022-45113

Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may…

Fix: 6.8.7 / 7.9.6+
Fix from $1,600 2022-12-07
Fortiadc MEDIUM 6.5
CVE-2022-33876

Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and b…

Fix: after 6.2.4
Fix from $1,600 2022-12-06
Gatemanager HIGH 7.2
CVE-2022-38123

Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the Gat…

Fix: 10.0.622395010+
Fix from $1,950 2022-12-06
Gitpython CRITICAL 9.8
CVE-2022-24439EPSS 5%

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inj…

Fix: 3.1.30+
Fix from $2,300 2022-12-06
Frontend CRITICAL 9.8
CVE-2022-43515

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this w…

Fix: after 6.2.4
Fix from $2,300 2022-12-05
Terasoluna Global Framework HIGH 7.8
CVE-2022-43484

TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a Clas…

Fix: after 2.0.5.1
Fix from $1,950 2022-12-05
Commons Net MEDIUM 6.5
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net co…

Fix: 3.9.0+
Fix from $1,600 2022-12-03
Snakeyaml CRITICAL 9.8
CVE-2022-1471EPSS 100%

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an a…

Fix: 2.0+
Fix from $2,300 2022-12-01
Rj71en71 Firmware HIGH 7.5
CVE-2022-40265

Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi…

Fix: after 65
Fix from $1,950 2022-11-30
Quiz And Survey Master MEDIUM 6.1
CVE-2022-4032

The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, …

Fix: after 8.0.4
Fix from $1,600 2022-11-29
Quiz And Survey Master MEDIUM 5.3
CVE-2022-4033

The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and incl…

Fix: after 8.0.4
Fix from $1,600 2022-11-29
Orion Platform HIGH 8.8
CVE-2022-36960

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Decode Uri Component HIGH 7.5
CVE-2022-38900EPSS 25%

decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.

No fix yet
Fix from $1,950 2022-11-28
Openid Connect User Backend MEDIUM 5.4
CVE-2022-39338

user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a store…

Fix: 1.2.1+
Fix from $1,600 2022-11-25
Nextcloud Enterprise Server MEDIUM 6.5
CVE-2022-39346

Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could…

Fix: 22.2.10 / 23.0.7+
Fix from $1,600 2022-11-25
Got2000 Gt27 Firmware MEDIUM 6.5
CVE-2022-40266

Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP server versions 01.39.000 and prior, Mitsubishi Electric…

Fix: after 01.39.000
Fix from $1,600 2022-11-24