Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Xplatform HIGH 8.8
CVE-2021-26626

Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the …

Fix: 9.2.2.280+
Fix from $1,950 2022-04-19
Debian Linux HIGH 7.8
CVE-2021-3624

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be exe…

No fix yet
Fix from $1,950 2022-04-18
Chamilo Lms HIGH 7.2
CVE-2022-27421

Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.

Fix: after 1.11.14
Fix from $1,950 2022-04-15
Gt.m HIGH 7.5
CVE-2021-44481

An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of parameter validation in calls to memcpy in check_and_set_timeout in sr_unix/…

Fix: after 7.0-000
Fix from $1,950 2022-04-15
Gt.m HIGH 7.5
CVE-2021-44482

An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attacke…

Fix: after 7.0-000
Fix from $1,950 2022-04-15
Gt.m HIGH 7.5
CVE-2021-44483

An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers …

Fix: after 7.0-000
Fix from $1,950 2022-04-15
iOS MEDIUM 6.5
CVE-2022-20761

A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an …

Mitigation only
Fix from $1,600 2022-04-15
Ios Xe MEDIUM 6.7
CVE-2022-20676

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from…

Mitigation only
Fix from $1,600 2022-04-15
Ios Xe HIGH 7.7
CVE-2022-20679

A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device …

Mitigation only
Fix from $1,950 2022-04-15
Ios Xe MEDIUM 6.5
CVE-2022-20684

A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for th…

Mitigation only
Fix from $1,600 2022-04-15
Geowebcache HIGH 7.2
CVE-2022-24846

GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn ca…

Fix: 1.19.3 / 1.20.2+
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44354

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44355

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44356

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44357

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44366

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44375

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Rlc 410w Firmware HIGH 7.5
CVE-2021-44394

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A sp…

No fix yet
Fix from $1,950 2022-04-14
Apweb CRITICAL 9.8
CVE-2022-28711

A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac - master branch 46177cb9. A sp…

No fix yet
Fix from $2,300 2022-04-14
Geoserver HIGH 7.2
CVE-2022-24847

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The GeoServer security mechanism can…

Fix: 2.19.6 / 2.20.4+
Fix from $1,950 2022-04-13
Geotools HIGH 7.2
CVE-2022-24818

GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of data sources that can perform u…

Fix: 24.6 / 25.6+
Fix from $1,950 2022-04-13
Fedora HIGH 8.8
CVE-2022-24828

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a cod…

Fix: 1.10.26 / 2.2.12+
Fix from $1,950 2022-04-13
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-27654

When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, t…

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-27655

When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the …

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26106

When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - v…

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26107

When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version …

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26108

When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26109

When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - ver…

Mitigation only
Fix from $1,600 2022-04-12
Scalance W1788 2ia M12 Firmware HIGH 7.5
CVE-2022-28328

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788…

Fix: 3.0.0+
Fix from $1,950 2022-04-12
Scalance W1788 2ia M12 Firmware MEDIUM 6.5
CVE-2022-28329

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788…

Fix: 3.0.0+
Fix from $1,600 2022-04-12