Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Splunk HIGH 8.8
CVE-2022-26889

In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an …

Fix: 8.1.2+
Fix from $1,950 2022-05-06
Ingress Nginx HIGH 8.1
CVE-2021-25745

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi…

Fix: 1.2.0+
Fix from $1,950 2022-05-06
Ingress Nginx HIGH 7.1
CVE-2021-25746

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress o…

Fix: 1.2.0+
Fix from $1,950 2022-05-06
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-29479

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Advanced Firewall Manager HIGH 7.2
CVE-2022-28695

On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior t…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2022-28708

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS prof…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager HIGH 7.2
CVE-2022-27634

On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authent…

Fix: 15.1.5.1 / 16.1.2.2+
Fix from $1,950 2022-05-05
Robotic Process Automation HIGH 7.5
CVE-2022-22433

IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied…

Fix: 21.0.1.5+
Fix from $1,950 2022-05-05
Enterprise Nfv Infrastructure Software HIGH 8.8
CVE-2022-20779EPSS 10%

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…

Fix: 4.7.1+
Fix from $1,950 2022-05-04
Android MEDIUM 6.7
CVE-2022-28781

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch …

Mitigation only
Fix from $1,600 2022-05-03
Android HIGH 7.1
CVE-2022-28783

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages withou…

Mitigation only
Fix from $1,950 2022-05-03
Galaxy Store MEDIUM 5.5
CVE-2022-28791

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a spec…

Fix: 4.5.41.8+
Fix from $1,600 2022-05-03
Secure Firewall Threat Defense HIGH 8.6
CVE-2022-20715

A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So…

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Secure Firewall Threat Defense HIGH 7.5
CVE-2022-20745

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower …

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Libxmljs HIGH 7.5
CVE-2022-21144

This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invok…

Fix: 0.19.8+
Fix from $1,950 2022-05-01
Httpx CRITICAL 9.1
CVE-2021-41945

Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

Fix: 0.23.0+
Fix from $2,300 2022-04-28
Jetson Linux MEDIUM 5.7
CVE-2022-28195

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may…

Fix: 32.7.2+
Fix from $1,600 2022-04-27
Jetson Linux MEDIUM 5.6
CVE-2022-28193

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may al…

Fix: 32.7.2+
Fix from $1,600 2022-04-27
Codegen CRITICAL 9.8
CVE-2022-24881

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote…

Fix: 1.0.0+
Fix from $2,300 2022-04-26
Mivoice Connect CRITICAL 9.8
CVE-2022-29499 KEVEPSS 55%

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Serv…

Fix: after 22.20.2300.0
Fix from $2,300 2022-04-26
A340 22icb Firmware MEDIUM 6.7
CVE-2021-4211

A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models…

Mitigation only
Fix from $1,600 2022-04-22
C340 14iml Firmware MEDIUM 6.7
CVE-2021-4212

A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with …

Patch available
Fix from $1,600 2022-04-22
Thinkpad 11e Firmware MEDIUM 6.7
CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some…

Mitigation only
Fix from $1,600 2022-04-22
Thinkpad X1 Fold Gen 1 Firmware MEDIUM 6.7
CVE-2022-1108

A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploite…

Mitigation only
Fix from $1,600 2022-04-22
Ideapad 3 14ada05 Firmware MEDIUM 6.7
CVE-2021-3970

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with…

Mitigation only
Fix from $1,600 2022-04-22
Stadia Ggp 120 Firmware MEDIUM 6.7
CVE-2021-4210

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow a…

Patch available
Fix from $1,600 2022-04-22
Integrated Dell Remote Access Controller 8 Firmware HIGH 7.5
CVE-2022-24423

Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this …

Fix: 2.83.83.83+
Fix from $1,950 2022-04-21
Telepresence Collaboration Endpoint HIGH 7.5
CVE-2022-20783

A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could all…

Fix: 9.15.10.8 / 10.11.2.2+
Fix from $1,950 2022-04-21
Databasir HIGH 8.8
CVE-2022-24861

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC dri…

Patch available
Fix from $1,950 2022-04-20
Ovn Kubernetes CRITICAL 9.1
CVE-2022-0567

A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses e…

Fix: 4.7.47 / 4.8.36+
Fix from $2,300 2022-04-20