Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32239

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr…

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32236

When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application…

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32237

When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual Enterprise Viewer…

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32235

When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the appl…

Fix: after 9.0
Fix from $1,600 2022-06-14
Sinema Remote Connect Server HIGH 7.5
CVE-2022-32253

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate'…

Fix: 3.1+
Fix from $1,950 2022-06-14
Ar8035 Firmware MEDIUM 5.9
CVE-2021-35111

Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile

Mitigation only
Fix from $1,600 2022-06-14
Apq8009 Firmware HIGH 7.1
CVE-2021-35116

APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon…

Mitigation only
Fix from $1,950 2022-06-14
Apq8053 Firmware MEDIUM 6.7
CVE-2021-35092

Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdrag…

Patch available
Fix from $1,600 2022-06-14
Sd850 Firmware MEDIUM 5.5
CVE-2021-30338

Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute

Mitigation only
Fix from $1,600 2022-06-14
Flume CRITICAL 9.8
CVE-2022-25167

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…

Fix: 1.10.0+
Fix from $2,300 2022-06-14
Electron HIGH 7.2
CVE-2022-29257

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18…

Fix: 15.5.0 / 16.2.0+
Fix from $1,950 2022-06-13
Emui HIGH 7.8
CVE-2022-31762

The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.

No fix yet
Fix from $1,950 2022-06-13
Open Forms MEDIUM 6.5
CVE-2022-31041

Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields c…

Fix: 1.0.9+
Fix from $1,600 2022-06-13
Keypad Secure Usb 3.2 Gen 1 Firmware MEDIUM 6.8
CVE-2022-28383

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmw…

Fix: after 2022-03-31
Fix from $1,600 2022-06-08
Txpert Hub Coretec 4 Firmware MEDIUM 6.7
CVE-2021-35531

Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacke…

Mitigation only
Fix from $1,600 2022-06-07
Kies HIGH 7.8
CVE-2022-30744

DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

Fix: 2.6.4.22043_1+
Fix from $1,950 2022-06-07
Android CRITICAL 9.1
CVE-2022-30711

Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30712

Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30713

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android MEDIUM 5.3
CVE-2022-30719

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30720

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30721

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android HIGH 7.8
CVE-2022-30726

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to la…

Mitigation only
Fix from $1,950 2022-06-07
Android MEDIUM 5.3
CVE-2022-30709

Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android CRITICAL 9.1
CVE-2022-30710

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Calico MEDIUM 5.5
CVE-2022-28224

Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floatin…

Fix: 3.11.4 / 3.20.5+
Fix from $1,600 2022-06-06
Powerlogic Ion Setup Firmware HIGH 8.8
CVE-2022-30232

A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and m…

Fix: 3.2.22096.01+
Fix from $1,950 2022-06-02
Wiser Smart Eer21000 Firmware MEDIUM 6.5
CVE-2022-30233

A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is tricked into per…

Fix: after 4.5
Fix from $1,600 2022-06-02
Melsec Iq R Rd81mes96n Firmware CRITICAL 9.8
CVE-2022-25163

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubis…

Fix: 09 / 24062+
Fix from $2,300 2022-06-02
Bigbluebutton HIGH 7.5
CVE-2022-29169

BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to re…

Fix: 2.3.19 / 2.4.7+
Fix from $1,950 2022-06-01