Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Fedora MEDIUM 6.5
CVE-2022-36087

OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malic…

Fix: 3.2.1+
Fix from $1,600 2022-09-09
Man2html MEDIUM 5.5
CVE-2021-40648

In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of th…

No fix yet
Fix from $1,600 2022-09-09
Linux Kernel MEDIUM 5.5
CVE-2022-3169

A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL…

Mitigation only
Fix from $1,600 2022-09-09
Galaxy Watch Plugin MEDIUM 6.5
CVE-2022-36873

Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the c…

Fix: 2.2.11.22081151+
Fix from $1,600 2022-09-09
Android HIGH 7.5
CVE-2022-36853

Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

Mitigation only
Fix from $1,950 2022-09-09
Android MEDIUM 5.5
CVE-2022-36854

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

Mitigation only
Fix from $1,600 2022-09-09
Open Policy Agent CRITICAL 9.8
CVE-2022-36085

Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, wh…

Fix: 0.43.1+
Fix from $2,300 2022-09-08
Mangadex Downloader MEDIUM 5.3
CVE-2022-36082

mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<location>` is a web URL locati…

Fix: 1.7.2+
Fix from $1,600 2022-09-07
Elrond Go HIGH 7.5
CVE-2022-36058

Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.34, anyone who uses elrond-go to process blocks (histori…

Fix: 1.3.34+
Fix from $1,950 2022-09-06
Http MEDIUM 5.3
CVE-2022-36032

ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component versions starting with 0.7.0 and…

Fix: 1.7.0+
Fix from $1,600 2022-09-06
Indy Node HIGH 8.8
CVE-2022-31020

Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` re…

Fix: after 1.12.4
Fix from $1,950 2022-09-06
Tigergraph HIGH 8.8
CVE-2022-30331

The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. C…

Mitigation only
Fix from $1,950 2022-09-05
Aqt1000 Firmware HIGH 7.8
CVE-2021-35122

Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdrag…

Mitigation only
Fix from $1,950 2022-09-02
Sd 8 Gen1 5g Firmware MEDIUM 6.8
CVE-2021-35109

Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in Snapdragon Connectivity, Sna…

Mitigation only
Fix from $1,600 2022-09-02
Data Plane Development Kit MEDIUM 6.5
CVE-2022-28199

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handle…

Fix: 20.11_5.0.0+
Fix from $1,600 2022-09-01
Jboss Data Grid HIGH 8.8
CVE-2022-1271

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a…

Fix: 1.12 / 5.2.5+
Fix from $1,950 2022-08-31
Keycloak MEDIUM 5.3
CVE-2021-3754

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may caus…

Mitigation only
Fix from $1,600 2022-08-26
B2236 Firmware HIGH 8.1
CVE-2022-29850

Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across r…

Mitigation only
Fix from $1,950 2022-08-26
Ansible Runner HIGH 7.8
CVE-2021-4041

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to pa…

Fix: 2.1.0+
Fix from $1,950 2022-08-24
Openshift HIGH 8.1
CVE-2021-4125

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J…

Fix: 4.6.52 / 4.7.40+
Fix from $1,950 2022-08-24
Linux Kernel HIGH 7.1
CVE-2021-4204

An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker…

Fix: 5.8.0+
Fix from $1,950 2022-08-24
Keycloak MEDIUM 5.4
CVE-2020-35509

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…

Mitigation only
Fix from $1,600 2022-08-23
Openshift Api Management MEDIUM 5.4
CVE-2021-3442

A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into s…

Mitigation only
Fix from $1,600 2022-08-22
Flume CRITICAL 9.8
CVE-2022-34916

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI …

Fix: 1.10.1+
Fix from $2,300 2022-08-21
Lapbc510 Firmware HIGH 7.8
CVE-2022-33209

Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable e…

Patch available
Fix from $1,950 2022-08-18
Lapbc510 Firmware MEDIUM 6.2
CVE-2022-34345

Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable e…

Patch available
Fix from $1,600 2022-08-18
Wireless Ac 9560 Firmware HIGH 7.8
CVE-2022-21181

Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escal…

Fix: 3.1122.1105 / 22.120+
Fix from $1,950 2022-08-18
Wireless Ac 9560 Firmware HIGH 7.5
CVE-2022-21197

Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service v…

Fix: 22.120+
Fix from $1,950 2022-08-18
Wireless Ac 9560 Firmware MEDIUM 6.5
CVE-2022-21212

Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service v…

Fix: 22.120+
Fix from $1,600 2022-08-18
Data Center Manager MEDIUM 5.5
CVE-2022-23403

Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denia…

Fix: 4.1+
Fix from $1,600 2022-08-18