Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Scalance X302 7eec Firmware HIGH 7.5
CVE-2022-25751

A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC…

Fix: 4.1.4+
Fix from $1,950 2022-04-12
Libiec61850 HIGH 7.5
CVE-2022-1302

In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which may result in a denial of se…

Fix: 1.5.1+
Fix from $1,950 2022-04-12
Smart Switch Pc HIGH 7.8
CVE-2022-27842

DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.

Fix: 4.2.22022_4+
Fix from $1,950 2022-04-11
Kies HIGH 7.8
CVE-2022-27843

DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

Fix: 2.6.4.22014_2+
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27826

Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27827

Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27828

Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27829

Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27830

Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27833

Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2022-27835

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.2
CVE-2022-27573

Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow…

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.2
CVE-2022-27574

Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow…

Mitigation only
Fix from $1,950 2022-04-11
Openshift HIGH 7.5
CVE-2021-4047

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only aff…

Mitigation only
Fix from $1,950 2022-04-11
Rt Ac86u Firmware MEDIUM 6.5
CVE-2022-25595

ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular req…

Mitigation only
Fix from $1,600 2022-04-07
Web Security Appliance MEDIUM 5.3
CVE-2022-20784

A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unaut…

Fix: 14.0.2+
Fix from $1,600 2022-04-06
Fortisandbox MEDIUM 5.4
CVE-2020-29013

An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt…

Fix: after 3.1.4
Fix from $1,600 2022-04-06
Uri.js MEDIUM 6.1
CVE-2022-1243

CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.

Fix: 1.19.11+
Fix from $1,600 2022-04-05
Nport Iaw5150a 6i\/o Firmware CRITICAL 9.8
CVE-2021-32974

Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to…

Fix: after 2.2
Fix from $2,300 2022-04-01
Escan Anti Virus HIGH 8.8
CVE-2021-26624

An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insu…

Fix: 7.0.31+
Fix from $1,950 2022-04-01
Nport Iaw5150a 6i\/o Firmware HIGH 7.5
CVE-2021-32970

Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a…

Fix: after 2.2
Fix from $1,950 2022-04-01
800xa HIGH 7.5
CVE-2021-22277

Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, AB…

Fix: 3.0 / 6.0.0-4+
Fix from $1,950 2022-04-01
Security Verify Access MEDIUM 6.5
CVE-2022-22311

IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some informatio…

Patch available
Fix from $1,600 2022-03-31
Pfsense HIGH 8.8
CVE-2022-24299

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…

Fix: 2.6.0 / 22.01+
Fix from $1,950 2022-03-31
Android HIGH 7.8
CVE-2021-39763

In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39764

In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39771

In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39778

In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This coul…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39740

In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclo…

Mitigation only
Fix from $1,600 2022-03-30
Apisix CRITICAL 9.8
CVE-2022-25757

In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…

Fix: 2.13.0+
Fix from $2,300 2022-03-28