Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Alienware Area 51m R1 Firmware HIGH 7.8
CVE-2022-32485

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.16 / 1.0.20+
Fix from $1,950 2022-10-12
Alienware Area 51m R1 Firmware HIGH 7.8
CVE-2022-32487

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.16 / 1.0.20+
Fix from $1,950 2022-10-12
Alienware Area 51m R1 Firmware HIGH 7.8
CVE-2022-32488

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.16 / 1.0.20+
Fix from $1,950 2022-10-12
Alienware Area 51m R1 Firmware HIGH 7.8
CVE-2022-32489

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.0.16 / 1.0.20+
Fix from $1,950 2022-10-12
Nomad MEDIUM 6.5
CVE-2022-41606

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to…

Fix: 1.2.13 / 1.3.6+
Fix from $1,600 2022-10-12
Debian Linux MEDIUM 6.3
CVE-2022-3140EPSS 6%

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…

Fix: 7.3.6+
Fix from $1,600 2022-10-11
Bios HIGH 8.8
CVE-2022-32486

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 2.21.0 / 2.25.0+
Fix from $1,950 2022-10-11
Bios HIGH 8.8
CVE-2022-32492

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 2.21.0 / 2.25.0+
Fix from $1,950 2022-10-11
Logo\! 8 Bm Firmware HIGH 7.5
CVE-2022-36362

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! …

Patch available
Fix from $1,950 2022-10-11
Logo\! 8 Bm Firmware MEDIUM 5.3
CVE-2022-36363

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO!…

Patch available
Fix from $1,600 2022-10-11
Simatic Hmi Comfort Panels Firmware HIGH 7.5
CVE-2022-40227

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panel…

Fix: 17.0+
Fix from $1,950 2022-10-11
Ruggedcom Rm1224 Firmware HIGH 8.6
CVE-2022-31766

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610…

Fix: 7.1.2+
Fix from $1,950 2022-10-11
Fedora MEDIUM 6.5
CVE-2022-42012

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-…

Fix: 1.12.24 / 1.14.4+
Fix from $1,600 2022-10-10
Fatfreecrm MEDIUM 6.5
CVE-2022-39281

fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user ca…

Fix: 0.20.1+
Fix from $1,600 2022-10-08
Zoneminder MEDIUM 5.4
CVE-2022-39291EPSS 5%

ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability whic…

Fix: 1.36.27 / 1.37.24+
Fix from $1,600 2022-10-07
Android HIGH 7.5
CVE-2022-32591

In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service with no additional execution p…

Mitigation only
Fix from $1,950 2022-10-07
Lief MEDIUM 6.5
CVE-2022-40923

A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) thro…

Patch available
Fix from $1,600 2022-09-30
Catalyst 9800 L Firmware MEDIUM 6.5
CVE-2022-20945

A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent…

Fix: 17.6.4+
Fix from $1,600 2022-09-30
Sd Wan Vbond Orchestrator HIGH 7.1
CVE-2022-20850

A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to dele…

Fix: 16.10.1 / 18.4.5+
Fix from $1,950 2022-09-30
Joplin HIGH 7.8
CVE-2022-40277

Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file,…

No fix yet
Fix from $1,950 2022-09-30
Goflow HIGH 7.5
CVE-2022-2529

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packe…

Fix: 3.4.4+
Fix from $1,950 2022-09-30
Isolated Vm CRITICAL 9.8
CVE-2022-39266

isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached da…

Fix: after 4.3.6
Fix from $2,300 2022-09-29
Virtualization HIGH 8.6
CVE-2014-0144

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/bu…

Patch available
Fix from $1,950 2022-09-29
PHP MEDIUM 6.5
CVE-2022-31629EPSS 49%

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the …

Fix: 7.4.31 / 8.0.24+
Fix from $1,600 2022-09-28
Javascript Sdk MEDIUM 5.3
CVE-2022-39236

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt …

Fix: 19.7.0+
Fix from $1,600 2022-09-28
Insydeh2o HIGH 8.2
CVE-2022-36448

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. There is an SMM memory corruption vulnerability in the Software SMI handler …

Fix: 05.44.30 / 05.52.30+
Fix from $1,950 2022-09-28
Cpy Car Park Server HIGH 7.2
CVE-2022-22525

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary co…

Fix: 2.8.3 / 8.5.0.3+
Fix from $1,950 2022-09-28
Chrome CRITICAL 9.6
CVE-2022-3075 KEVEPSS 6%

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to p…

Fix: 105.0.5195.102+
Fix from $2,300 2022-09-26
Chrome MEDIUM 5.4
CVE-2022-3201

Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user…

Fix: 105.0.5195.125+
Fix from $1,600 2022-09-26
Chrome MEDIUM 6.5
CVE-2022-2856 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily br…

Fix: 104.0.5112.101 / 104.0.5112.102+
Fix from $1,600 2022-09-26