Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Commerce HIGH 7.5
CVE-2021-26631

Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vu…

Fix: 1.3.9+
Fix from $1,950 2022-05-19
Melsec Iq Fx5u 32mt\/es Firmware HIGH 8.6
CVE-2022-25161

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 1…

Fix: 1.270+
Fix from $1,950 2022-05-18
Melsec Iq Fx5u 32mt\/es Firmware MEDIUM 5.3
CVE-2022-25162

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 1…

Fix: 1.270+
Fix from $1,600 2022-05-18
Drawio HIGH 8.8
CVE-2022-1727

Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.

Fix: 18.0.6+
Fix from $1,950 2022-05-18
Gpu Display Driver MEDIUM 5.5
CVE-2022-28188

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product r…

Fix: 11.8 / 13.3+
Fix from $1,600 2022-05-17
Gpu Display Driver MEDIUM 5.5
CVE-2022-28190

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper inpu…

Patch available
Fix from $1,600 2022-05-17
Gpu Display Driver MEDIUM 6.1
CVE-2022-28186

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product r…

Fix: 11.8 / 13.3+
Fix from $1,600 2022-05-17
Xarrow HIGH 7.8
CVE-2021-33025

xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

Fix: after 7.2
Fix from $1,950 2022-05-16
Ryzen 3 3100 Firmware MEDIUM 5.5
CVE-2021-26351

Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM addre…

Mitigation only
Fix from $1,600 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26781

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A spec…

Fix: after 3.5.37
Fix from $1,950 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26782

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A spec…

Fix: after 3.5.37
Fix from $1,950 2022-05-12
Lapbc510 Firmware MEDIUM 6.7
CVE-2022-24382

Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local acce…

Patch available
Fix from $1,600 2022-05-12
Ir302 Firmware HIGH 8.8
CVE-2022-26780

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A spec…

Fix: after 3.5.37
Fix from $1,950 2022-05-12
In Band Manageability MEDIUM 6.7
CVE-2021-33108

Improper input validation in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable esca…

Fix: after 2.13.0
Fix from $1,600 2022-05-12
Core I9 7940x Firmware MEDIUM 5.5
CVE-2022-21136

Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.

Mitigation only
Fix from $1,600 2022-05-12
Manageability Commander HIGH 8.0
CVE-2021-0126

Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalatio…

Fix: 2.2+
Fix from $1,950 2022-05-12
Xeon E 2314 Firmware HIGH 7.8
CVE-2021-0154

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privileg…

Mitigation only
Fix from $1,950 2022-05-12
Xeon Bronze 3204 Firmware HIGH 7.8
CVE-2021-0159

Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescal…

Mitigation only
Fix from $1,950 2022-05-12
Ti Pg1284i Firmware CRITICAL 9.8
CVE-2021-33315

The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its …

Fix: 2.0.2.s0+
Fix from $2,300 2022-05-11
Ti Pg1284i Firmware CRITICAL 9.8
CVE-2021-33316

The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its …

Fix: 2.0.2.s0+
Fix from $2,300 2022-05-11
Epyc 7232p Firmware MEDIUM 5.5
CVE-2021-26373

Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and…

Mitigation only
Fix from $1,600 2022-05-11
Rad Ism 900 En Bd Firmware CRITICAL 9.1
CVE-2022-29897

On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary co…

Mitigation only
Fix from $2,300 2022-05-11
GitLab MEDIUM 6.5
CVE-2022-1406

Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 all…

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-11
GitLab MEDIUM 5.3
CVE-2022-1431

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all v…

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-10
Epyc 7763 Firmware HIGH 7.8
CVE-2021-46771

Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a comprom…

Mitigation only
Fix from $1,950 2022-05-10
Epyc 7763 Firmware HIGH 7.1
CVE-2021-26370

Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an att…

Mitigation only
Fix from $1,950 2022-05-10
Keepkey Firmware MEDIUM 6.6
CVE-2022-30330

In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operati…

Fix: 7.3.2+
Fix from $1,600 2022-05-07
Photoshop HIGH 7.8
CVE-2022-24098

Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX f…

Fix: after 23.2.2
Fix from $1,950 2022-05-06
Hcl Inotes MEDIUM 5.5
CVE-2021-27760

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote C…

Mitigation only
Fix from $1,600 2022-05-06
Fedora CRITICAL 9.1
CVE-2022-1053

Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifi…

Fix: 6.4.0+
Fix from $2,300 2022-05-06