Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Poi MEDIUM 5.5
CVE-2022-26336

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read…

Fix: 5.2.1+
Fix from $1,600 2022-03-04
Uri.js MEDIUM 5.3
CVE-2022-24723

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs…

Fix: 1.19.9+
Fix from $1,600 2022-03-03
Samba HIGH 7.5
CVE-2021-23192

A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an …

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-03-02
Firewall CRITICAL 9.8
CVE-2022-0675

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manif…

Fix: 3.4.0+
Fix from $2,300 2022-03-02
Image Processing CRITICAL 9.8
CVE-2022-24720

image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from i…

Fix: 1.12.2+
Fix from $2,300 2022-03-01
Fortimail CRITICAL 9.8
CVE-2021-32586

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter …

Fix: 6.0.12 / 6.2.8+
Fix from $2,300 2022-03-01
Codeigniter CRITICAL 9.8
CVE-2022-24711

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability all…

Fix: 4.1.9+
Fix from $2,300 2022-02-28
Firstmall CRITICAL 9.8
CVE-2021-26617

This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute mali…

Mitigation only
Fix from $2,300 2022-02-25
Nx Os HIGH 7.5
CVE-2022-20624EPSS 12%

A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to caus…

Mitigation only
Fix from $1,950 2022-02-23
Tooffice CRITICAL 9.8
CVE-2021-26618

An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to exec…

Fix: 3.15.6+
Fix from $2,300 2022-02-18
Debian Linux HIGH 8.1
CVE-2020-25717

A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…

Patch available
Fix from $1,950 2022-02-18
Snapd HIGH 7.8
CVE-2021-4120

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrar…

Fix: after 2.54.2
Fix from $1,950 2022-02-17
Redundancy Configuration Manager HIGH 7.5
CVE-2022-20750

A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software could allow an una…

Fix: 21.24.0+
Fix from $1,950 2022-02-17
Drupal HIGH 7.5
CVE-2022-25271

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co…

Fix: 7.88 / 9.2.13+
Fix from $1,950 2022-02-16
Fedora CRITICAL 9.9
CVE-2021-3781EPSS 84%

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe comm…

Patch available
Fix from $2,300 2022-02-16
Commerce CRITICAL 9.8
CVE-2022-24086 KEVEPSS 99%

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the check…

Fix: 2.3.0+
Fix from $2,300 2022-02-16
Xcom Data Transport CRITICAL 9.8
CVE-2022-23992

XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially al…

Mitigation only
Fix from $2,300 2022-02-14
Camera MEDIUM 5.5
CVE-2022-23998

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(…

Fix: 9.0.6.68 / 10.5.03.77+
Fix from $1,600 2022-02-11
Android MEDIUM 6.5
CVE-2022-24925

Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servi…

Mitigation only
Fix from $1,600 2022-02-11
Smarttagplugin MEDIUM 5.4
CVE-2022-24926

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's device…

Fix: 1.2.15-6+
Fix from $1,600 2022-02-11
Android CRITICAL 9.8
CVE-2022-23425

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base…

Mitigation only
Fix from $2,300 2022-02-11
Android HIGH 7.1
CVE-2022-23427

PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files witho…

Mitigation only
Fix from $1,950 2022-02-11
Android MEDIUM 6.7
CVE-2022-23432

An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,600 2022-02-11
Android HIGH 7.8
CVE-2021-39676

In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This cou…

Mitigation only
Fix from $1,950 2022-02-11
Modicon M340 Bmxp342020 Firmware HIGH 7.5
CVE-2021-22787

A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted …

Fix: 3.40+
Fix from $1,950 2022-02-11
Modicon M218 Firmware HIGH 7.5
CVE-2021-22800

A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over ne…

Fix: after 5.1.0.6
Fix from $1,950 2022-02-11
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22537

When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versio…

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22538

When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - vers…

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22539

When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…

Mitigation only
Fix from $1,600 2022-02-09
Android MEDIUM 5.5
CVE-2022-20036

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2022-02-09