Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Killer Wifi Software MEDIUM 6.5
CVE-2022-26047

Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user…

Fix: 2.2.14.22176 / 3.1122.3158+
Fix from $1,600 2022-11-11
Core I5 7640x Firmware MEDIUM 6.7
CVE-2022-26006

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege…

Mitigation only
Fix from $1,600 2022-11-11
Openvino MEDIUM 6.5
CVE-2021-26251

Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of servic…

Fix: 2021.4.2+
Fix from $1,600 2022-11-11
M10jnp2sb Firmware MEDIUM 6.7
CVE-2021-0185

Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a privileged user to potentiall…

Fix: 7.216+
Fix from $1,600 2022-11-10
Android HIGH 7.8
CVE-2022-39880

Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code exec…

Mitigation only
Fix from $1,950 2022-11-09
Exynos Firmware CRITICAL 9.1
CVE-2022-39881

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of…

Mitigation only
Fix from $2,300 2022-11-09
Grafana HIGH 8.1
CVE-2022-39306

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper In…

Fix: 8.5.15 / 9.2.4+
Fix from $1,950 2022-11-09
Harmonyos MEDIUM 5.3
CVE-2022-44553

The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successfu…

Mitigation only
Fix from $1,600 2022-11-09
Amd Uprof HIGH 7.5
CVE-2022-27674

Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows …

Fix: 3.6.449 / 3.6.549+
Fix from $1,950 2022-11-09
Amd Uprof HIGH 7.5
CVE-2022-23831

Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kerne…

Fix: 3.6.449 / 3.6.549+
Fix from $1,950 2022-11-09
Fedora HIGH 7.5
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may in…

Fix: 6.0.11 / 7.1.2+
Fix from $1,950 2022-11-09
Netweaver Application Server Abap HIGH 8.7
CVE-2022-41214

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a …

Mitigation only
Fix from $1,950 2022-11-08
Android MEDIUM 5.5
CVE-2022-20457

In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This …

Mitigation only
Fix from $1,600 2022-11-08
Emui HIGH 7.5
CVE-2022-44556

Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2022-11-08
7kg9501 0aa01 2aa1 Firmware HIGH 8.8
CVE-2022-43439

A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1…

Fix: 2.50+
Fix from $1,950 2022-11-08
7kg9501 0aa01 2aa1 Firmware HIGH 8.8
CVE-2022-43545

A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICA…

Fix: 2.50+
Fix from $1,950 2022-11-08
7kg9501 0aa01 2aa1 Firmware HIGH 8.8
CVE-2022-43546

A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICA…

Fix: 2.50+
Fix from $1,950 2022-11-08
Splunk HIGH 8.8
CVE-2022-43565

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker byp…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Splunk HIGH 8.0
CVE-2022-43566

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Splunk MEDIUM 5.4
CVE-2022-43562

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk HIGH 8.8
CVE-2022-43563

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Openharmony MEDIUM 5.5
CVE-2022-43449

OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious applicat…

Fix: after 3.1.2
Fix from $1,600 2022-11-03
Infosphere Information Server MEDIUM 6.5
CVE-2022-40235

"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input val…

Patch available
Fix from $1,600 2022-11-03
Zettlr MEDIUM 5.5
CVE-2022-40276

Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown fi…

No fix yet
Fix from $1,600 2022-11-03
Fedora Coreos MEDIUM 5.5
CVE-2022-3675

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the…

Fix: 37.20221031.1.0+
Fix from $1,600 2022-11-03
Glpi MEDIUM 6.5
CVE-2022-39376

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk feat…

Fix: 10.0.4+
Fix from $1,600 2022-11-03
Vtscada HIGH 7.5
CVE-2022-3181

An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause t…

Fix: after 12.0.38
Fix from $1,950 2022-11-02
Debian Linux CRITICAL 9.8
CVE-2022-39353

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-form…

Fix: 0.6.0 / 0.7.7+
Fix from $2,300 2022-11-02
Chrome HIGH 8.8
CVE-2022-3656

Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via …

Fix: 107.0.5304.62+
Fix from $1,950 2022-11-01
Ipados HIGH 7.8
CVE-2022-42800

This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadO…

Fix: 9.1 / 11.7.1+
Fix from $1,950 2022-11-01