Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Caribou HIGH 7.5
CVE-2021-3567

A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that lev…

Fix: 0.4.21+
Fix from $1,950 2022-03-25
Cscape Envisionrv HIGH 7.1
CVE-2021-44462

This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The is…

Fix: after 4.50.3.1
Fix from $1,950 2022-03-25
Genian Nac CRITICAL 10.0
CVE-2021-26622

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote…

Fix: after 5.0.42.0827
Fix from $2,300 2022-03-25
Splunk HIGH 7.5
CVE-2021-3422

The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured…

Fix: 7.3.9 / 8.0.9+
Fix from $1,950 2022-03-25
Webhelpdesk HIGH 8.8
CVE-2021-35254

SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to…

Fix: 12.7.8+
Fix from $1,950 2022-03-25
Data Center Gpu Manager MEDIUM 6.3
CVE-2022-21820EPSS 17%

NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to …

Fix: 2.3.5+
Fix from $1,600 2022-03-24
Cmc HIGH 7.2
CVE-2022-0550

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin…

Fix: 22.0.0+
Fix from $1,950 2022-03-24
Cmc HIGH 7.2
CVE-2022-0551

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or imp…

Fix: 22.0.0+
Fix from $1,950 2022-03-24
Imagemagick MEDIUM 5.5
CVE-2021-4219

A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an…

Fix: 6.9.12-9 / 7.1.0-19+
Fix from $1,600 2022-03-23
Multilin B30 Firmware MEDIUM 6.1
CVE-2021-27418

GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making …

Fix: 8.10+
Fix from $1,600 2022-03-23
Multilin B30 Firmware MEDIUM 5.3
CVE-2021-27420

GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server…

Fix: 8.10+
Fix from $1,600 2022-03-23
Traffic Server HIGH 7.5
CVE-2021-44040

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affe…

Fix: after 9.1.1
Fix from $1,950 2022-03-23
Bitrix24 CRITICAL 9.8
CVE-2022-27228EPSS 21%

In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

Fix: 21.0.100+
Fix from $2,300 2022-03-22
Bill Of Materials Repository Server HIGH 8.1
CVE-2022-24774

CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server befor…

Fix: 2.0.1+
Fix from $1,950 2022-03-22
Drupal HIGH 7.5
CVE-2022-24775

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak…

Fix: 1.8.4 / 2.1.1+
Fix from $1,950 2022-03-21
Gogs HIGH 8.8
CVE-2022-0415EPSS 65%

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

Fix: 0.12.6+
Fix from $1,950 2022-03-21
Ipados MEDIUM 5.5
CVE-2022-22588EPSS 10%

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a malicious…

Fix: 15.2.1+
Fix from $1,600 2022-03-18
Android HIGH 7.8
CVE-2021-39701

In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or pe…

Patch available
Fix from $1,950 2022-03-16
Samba HIGH 8.8
CVE-2020-25721

Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a …

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-03-16
Url Js MEDIUM 5.3
CVE-2022-25839

The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to b…

Fix: 2.1.0+
Fix from $1,600 2022-03-11
Datapower Gateway MEDIUM 5.3
CVE-2021-38910

IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of…

Fix: after 2018.4.1.18
Fix from $1,600 2022-03-10
Sapcar CRITICAL 9.8
CVE-2022-26100

SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacke…

Mitigation only
Fix from $2,300 2022-03-10
Android CRITICAL 9.8
CVE-2022-25818

Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

Mitigation only
Fix from $2,300 2022-03-10
Steelcentral Appinternals Dynamic Sampling Agent MEDIUM 5.3
CVE-2021-42857

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/a…

Fix: 11.8.8 / 12.13.0+
Fix from $1,600 2022-03-10
Steelcentral Appinternals Dynamic Sampling Agent MEDIUM 6.1
CVE-2021-42856

It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not…

Fix: 11.8.8 / 12.13.0+
Fix from $1,600 2022-03-10
Steelcentral Appinternals Dynamic Sampling Agent CRITICAL 9.8
CVE-2021-42853

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at t…

Fix: 11.8.8 / 12.13.0+
Fix from $2,300 2022-03-10
Steelcentral Appinternals Dynamic Sampling Agent CRITICAL 9.8
CVE-2021-42854

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/ap…

Fix: 11.8.8 / 12.13.0+
Fix from $2,300 2022-03-10
Steelcentral Appinternals Dynamic Sampling Agent CRITICAL 9.8
CVE-2021-42786

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of …

Fix: 11.8.8 / 12.13.0+
Fix from $2,300 2022-03-10
Steelcentral Appinternals Dynamic Sampling Agent CRITICAL 9.8
CVE-2021-42787

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities…

Fix: 11.8.8 / 12.13.0+
Fix from $2,300 2022-03-10
Debian Linux MEDIUM 5.5
CVE-2021-20302

A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be process…

Fix: 2.5.4+
Fix from $1,600 2022-03-04