Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iphone Os MEDIUM 6.5
CVE-2022-22658

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 16.0.3. Processing a maliciously crafted email mes…

Fix: 16.0.3+
Fix from $1,600 2022-11-01
Muhammara HIGH 7.5
CVE-2022-25885

The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with…

Fix: 2.6.0+
Fix from $1,950 2022-11-01
Hubshare MEDIUM 5.4
CVE-2022-39017

Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce…

Fix: 3.3.10.9+
Fix from $1,600 2022-10-31
Hubshare HIGH 8.8
CVE-2022-39016

Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF u…

Fix: 3.3.10.9+
Fix from $1,950 2022-10-31
Meetings CRITICAL 9.6
CVE-2022-28763

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a …

Fix: 5.12.2+
Fix from $2,300 2022-10-31
Openlitespeed HIGH 8.8
CVE-2022-0073EPSS 9%

Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injecti…

Fix: after 1.7.16.1
Fix from $1,950 2022-10-27
Dart Software Development Kit CRITICAL 9.8
CVE-2022-3095

The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG U…

Fix: 2.18.0 / 3.3.3+
Fix from $2,300 2022-10-27
Metabase HIGH 8.8
CVE-2022-39361

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) c…

Fix: 0.41.9 / 0.42.6+
Fix from $1,950 2022-10-26
Flume CRITICAL 9.8
CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…

Fix: after 1.10.1
Fix from $2,300 2022-10-26
Identity Services Engine HIGH 8.1
CVE-2022-20822

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read a…

Mitigation only
Fix from $1,950 2022-10-26
Fabric Operating System HIGH 7.2
CVE-2022-33178

A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitr…

Fix: 9.0.0+
Fix from $1,950 2022-10-25
Illustrator HIGH 7.8
CVE-2022-38435

Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result i…

Fix: after 26.4
Fix from $1,950 2022-10-25
Dataease CRITICAL 9.8
CVE-2022-39312

Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat…

Fix: 1.15.2+
Fix from $2,300 2022-10-25
Openj9 MEDIUM 6.5
CVE-2022-3676

In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlin…

Fix: 0.35.0+
Fix from $1,600 2022-10-24
Iac Ast2500a Firmware MEDIUM 6.5
CVE-2021-44769

An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition…

Mitigation only
Fix from $1,600 2022-10-24
Jadx MEDIUM 5.5
CVE-2022-39259

jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prior to 1.4.5 are subject to a D…

Fix: 1.4.5+
Fix from $1,600 2022-10-21
Big Ip Advanced Firewall Manager MEDIUM 6.5
CVE-2022-41813

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or …

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,600 2022-10-19
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2022-41836

When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd proce…

Fix: 15.1.7 / 16.1.3.1+
Fix from $1,950 2022-10-19
3scale Api Management HIGH 8.8
CVE-2022-1414

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject s…

Mitigation only
Fix from $1,950 2022-10-19
Junos Os Evolved HIGH 7.5
CVE-2022-22247

An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows a network-based unauthentica…

Mitigation only
Fix from $1,950 2022-10-18
Junos HIGH 7.5
CVE-2022-22228

An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker …

Mitigation only
Fix from $1,950 2022-10-18
Junos MEDIUM 6.5
CVE-2022-22230

An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent …

Mitigation only
Fix from $1,600 2022-10-18
Junos CRITICAL 9.8
CVE-2022-22241

An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data w…

Fix: 19.1+
Fix from $2,300 2022-10-18
Junos Os Evolved HIGH 7.5
CVE-2022-22192

An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a netw…

Mitigation only
Fix from $1,950 2022-10-18
Junos HIGH 7.5
CVE-2022-22201

An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos…

Fix: 19.4+
Fix from $1,950 2022-10-18
Junos HIGH 7.5
CVE-2022-22223

On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (PHP) nodes with link aggregati…

Fix: 15.1+
Fix from $1,950 2022-10-18
Smart Wing Cms CRITICAL 9.8
CVE-2022-23770

This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remot…

Fix: 19051+
Fix from $2,300 2022-10-17
Coldfusion HIGH 7.5
CVE-2022-42340EPSS 34%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could re…

Mitigation only
Fix from $1,950 2022-10-14
Emui HIGH 7.5
CVE-2022-38985

The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.

Mitigation only
Fix from $1,950 2022-10-14
Google Protobuf HIGH 7.5
CVE-2022-3171

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service a…

Fix: 3.16.3 / 3.19.6+
Fix from $1,950 2022-10-12