Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-34844

In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elas…

Fix: 15.1.6.1 / 16.1.3.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-34851

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BI…

Fix: 14.1.5.1 / 15.1.6.1+
Fix from $1,600 2022-08-04
Nginx Ingress Controller MEDIUM 6.5
CVE-2022-30535

In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to …

Fix: 2.3.0+
Fix from $1,600 2022-08-04
Next Auth CRITICAL 9.1
CVE-2022-35924

NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in…

Fix: 3.29.10 / 4.10.3+
Fix from $2,300 2022-08-02
Fedora HIGH 7.4
CVE-2022-29154

An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peer…

Fix: 3.2.5+
Fix from $1,950 2022-08-02
Bolt CRITICAL 9.1
CVE-2022-31321

The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or caus…

Fix: after 5.7
Fix from $2,300 2022-08-01
Cics Tx MEDIUM 5.5
CVE-2022-34164

IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X-Force ID: 229338.

Patch available
Fix from $1,600 2022-08-01
Ecos Rsdk Firmware CRITICAL 9.8
CVE-2022-27255EPSS 37%

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker…

Mitigation only
Fix from $2,300 2022-08-01
Armor Compact Guardlogix 5370 Firmware HIGH 8.6
CVE-2020-6998

The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficient…

Fix: after 33
Fix from $1,950 2022-07-27
Chrome MEDIUM 6.5
CVE-2022-1500

Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a c…

Fix: 101.0.4951.41+
Fix from $1,600 2022-07-26
Moodle CRITICAL 9.8
CVE-2022-35649EPSS 8%

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i…

Fix: 3.9.15 / 3.11.8+
Fix from $2,300 2022-07-25
Moodle HIGH 7.5
CVE-2022-35650EPSS 49%

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in…

Fix: 3.9.15 / 3.11.8+
Fix from $1,950 2022-07-25
Obsidian CRITICAL 9.8
CVE-2022-36450EPSS 20%

Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the UR…

Fix: 0.15.5+
Fix from $2,300 2022-07-25
Contracts HIGH 7.5
CVE-2022-31170

OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of r…

Fix: 4.7.1+
Fix from $1,950 2022-07-22
Contracts HIGH 7.5
CVE-2022-31172

OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `Sig…

Fix: 4.7.1+
Fix from $1,950 2022-07-22
Nexus Dashboard MEDIUM 6.7
CVE-2022-20908

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…

Fix: 2.2+
Fix from $1,600 2022-07-22
Nexus Dashboard MEDIUM 6.7
CVE-2022-20909

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…

Fix: 2.2+
Fix from $1,600 2022-07-22
Nexus Dashboard MEDIUM 6.5
CVE-2022-20913

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerabi…

Fix: 2.2+
Fix from $1,600 2022-07-22
Junos MEDIUM 6.5
CVE-2022-22214

An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent…

Fix: 12.3 / 20.4+
Fix from $1,600 2022-07-20
Passage Drive HIGH 7.8
CVE-2022-34866

Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interp…

Fix: after 1.5.1.0
Fix from $1,950 2022-07-20
Manageengine Opmanager HIGH 8.2
CVE-2022-35404

ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…

Fix: 12.5+
Fix from $1,950 2022-07-18
Pexip Infinity HIGH 7.5
CVE-2022-26655

Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a software abort via a gateway call …

Fix: 27.3+
Fix from $1,950 2022-07-17
S\/4hana MEDIUM 5.3
CVE-2022-32248

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or…

Mitigation only
Fix from $1,600 2022-07-12
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-35171

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr…

Mitigation only
Fix from $1,600 2022-07-12
Aws Iam Authenticator HIGH 8.8
CVE-2022-2385

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privile…

Fix: 0.5.9+
Fix from $1,950 2022-07-12
Android HIGH 7.8
CVE-2022-33703

Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2022-07-12
Android HIGH 7.8
CVE-2022-33704

Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2022-07-12
Galaxy Store HIGH 7.8
CVE-2022-33708

Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities…

Fix: 4.5.41.8+
Fix from $1,950 2022-07-12
Galaxy Store HIGH 7.8
CVE-2022-33709

Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities…

Fix: 4.5.41.8+
Fix from $1,950 2022-07-12
Galaxy Store HIGH 7.8
CVE-2022-33710

Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activit…

Fix: 4.5.41.8+
Fix from $1,950 2022-07-12