Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Killer Ac 1550 Firmware MEDIUM 6.5
CVE-2021-44545

Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable…

Fix: 3.1122.1105 / 22.120+
Fix from $1,600 2022-08-18
Fabric MEDIUM 5.3
CVE-2022-36023

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client ap…

Fix: 2.4.6+
Fix from $1,600 2022-08-18
Fedora MEDIUM 5.5
CVE-2022-2868

libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is ab…

Fix: 4.4.0+
Fix from $1,600 2022-08-17
Smart Wing Cms HIGH 7.5
CVE-2021-26639

This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this v…

Mitigation only
Fix from $1,950 2022-08-17
Moodle HIGH 7.2
CVE-2020-1756

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

Fix: 3.5.11 / 3.6.9+
Fix from $1,950 2022-08-16
Sv Cpt Mc310f Firmware HIGH 8.8
CVE-2022-35239

The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficien…

Fix: 7.24+
Fix from $1,950 2022-08-16
Eternal Terminal MEDIUM 6.5
CVE-2022-24952

Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an invalid sequence…

Fix: 6.2.0+
Fix from $1,600 2022-08-16
Chrome MEDIUM 6.5
CVE-2022-2618

Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrict…

Fix: 104.0.5112.79+
Fix from $1,600 2022-08-12
Android MEDIUM 6.7
CVE-2022-20314

In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could lead to local escalation of pri…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.0
CVE-2022-20266

In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to impro…

Mitigation only
Fix from $1,600 2022-08-12
Virtual Desktop Infrastructure MEDIUM 6.1
CVE-2022-28755

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a…

Fix: 5.10.7 / 5.11.0+
Fix from $1,600 2022-08-11
Acrobat Dc HIGH 7.8
CVE-2022-35666EPSS 7%

Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an Improper Input…

Fix: after 22.001.20169
Fix from $1,950 2022-08-11
Acrobat Dc MEDIUM 5.5
CVE-2022-35668

Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an Improper Input…

Fix: after 22.001.20169
Fix from $1,600 2022-08-11
Studio CRITICAL 9.8
CVE-2021-22289

Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network a…

Mitigation only
Fix from $2,300 2022-08-11
Android MEDIUM 5.5
CVE-2022-20355

In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service…

Patch available
Fix from $1,600 2022-08-10
Android HIGH 7.8
CVE-2022-20356

In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improp…

Patch available
Fix from $1,950 2022-08-10
Android MEDIUM 5.5
CVE-2022-20350

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app…

Patch available
Fix from $1,600 2022-08-10
Android MEDIUM 5.5
CVE-2022-20353

In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to…

Patch available
Fix from $1,600 2022-08-10
Rv340 Firmware CRITICAL 9.8
CVE-2022-20842

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe…

Fix: 1.0.03.28+
Fix from $2,300 2022-08-10
Rv160 Firmware CRITICAL 9.0
CVE-2022-20841

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe…

Fix: 1.0.01.05 / 1.0.03.26+
Fix from $2,300 2022-08-10
Traffic Server HIGH 7.5
CVE-2021-37150

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-28129

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue af…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31778

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. Thi…

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31779

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects …

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Traffic Server HIGH 7.5
CVE-2022-31780

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects …

Fix: after 9.1.2
Fix from $1,950 2022-08-10
Azure Real Time Operating System Guix Studio HIGH 7.8
CVE-2022-35773

Azure RTOS GUIX Studio Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-35724

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin…

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Avro HIGH 7.5
CVE-2022-36125

It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust …

Fix: 0.14.0+
Fix from $1,950 2022-08-09
Android MEDIUM 5.5
CVE-2022-33715

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of …

Mitigation only
Fix from $1,600 2022-08-05
Android CRITICAL 9.8
CVE-2022-33719

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

Mitigation only
Fix from $2,300 2022-08-05