Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ar8031 Firmware HIGH 8.8
CVE-2021-30285

Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi…

Mitigation only
Fix from $1,950 2022-01-13
Spicedb HIGH 8.1
CVE-2022-21646

SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right h…

Patch available
Fix from $1,950 2022-01-11
6md85 Firmware HIGH 7.5
CVE-2021-41769

A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP3…

Fix: 8.83+
Fix from $1,950 2022-01-11
Fedora HIGH 8.6
CVE-2022-21668

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen…

Fix: 2022.1.8+
Fix from $1,950 2022-01-10
Debian Linux HIGH 8.8
CVE-2021-21408

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.…

Fix: 3.1.43 / 4.0.3+
Fix from $1,950 2022-01-10
Android HIGH 7.1
CVE-2022-22264

Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files withou…

Mitigation only
Fix from $1,950 2022-01-10
Security Verify Access HIGH 7.5
CVE-2021-38957

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. …

Patch available
Fix from $1,950 2022-01-10
Serv U MEDIUM 5.3
CVE-2021-35247 KEV

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani…

Fix: 15.3+
Fix from $1,600 2022-01-10
Insydeh2o HIGH 7.5
CVE-2020-5956

An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before …

Fix: 05.15.11 / 5.25.11+
Fix from $1,950 2022-01-05
Addressing CRITICAL 9.9
CVE-2021-43779EPSS 9%

GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers fro…

Fix: 2.9.1+
Fix from $2,300 2022-01-05
Django HIGH 7.5
CVE-2021-45116

An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variab…

Fix: 2.2.26 / 3.2.11+
Fix from $1,950 2022-01-05
Discourse MEDIUM 6.8
CVE-2021-43850

Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/mes…

Fix: 2.7.12+
Fix from $1,600 2022-01-04
Android MEDIUM 5.5
CVE-2022-20019

In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with…

Mitigation only
Fix from $1,600 2022-01-04
Android MEDIUM 5.5
CVE-2022-20020

In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no ad…

Mitigation only
Fix from $1,600 2022-01-04
Mt7615 Firmware MEDIUM 6.5
CVE-2021-41789

In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of service from a proximal attac…

Mitigation only
Fix from $1,600 2022-01-04
Harmonyos CRITICAL 9.1
CVE-2021-37116

PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscr…

Fix: 2.0+
Fix from $2,300 2022-01-03
Stars Rating HIGH 7.5
CVE-2021-24893

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Servi…

Fix: 3.5.1+
Fix from $1,950 2022-01-03
Ar8031 Firmware MEDIUM 5.5
CVE-2021-30278

Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdrago…

Mitigation only
Fix from $1,600 2022-01-03
Mermaid MEDIUM 5.4
CVE-2021-43861

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex …

Fix: 8.13.8+
Fix from $1,600 2021-12-30
Log4j MEDIUM 6.6
CVE-2021-44832EPSS 98%

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…

Fix: 2.3.2 / 2.12.4+
Fix from $1,600 2021-12-28
Patient Information Center Ix MEDIUM 6.5
CVE-2021-43548

Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input h…

Mitigation only
Fix from $1,600 2021-12-27
Simple Asn1 HIGH 7.5
CVE-2021-45711

An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a …

Mitigation only
Fix from $1,950 2021-12-27
Raw Cpuid CRITICAL 9.8
CVE-2021-45687

An issue was discovered in the raw-cpuid crate before 9.1.1 for Rust. If the serialize feature is used (which is not the the default), a Deserialize …

Fix: 9.1.1+
Fix from $2,300 2021-12-27
Mt7603e Firmware HIGH 7.5
CVE-2021-41788

MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected …

Mitigation only
Fix from $1,950 2021-12-26
Solr CRITICAL 9.8
CVE-2021-44548EPSS 5%

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…

Fix: 8.11.1+
Fix from $2,300 2021-12-23
Chrome HIGH 8.8
CVE-2021-38015

Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extensio…

Fix: 96.0.4664.45+
Fix from $1,950 2021-12-23
Chrome MEDIUM 6.5
CVE-2021-4059

Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Fix: 96.0.4664.93+
Fix from $1,600 2021-12-23
Drawings Sdk HIGH 7.8
CVE-2021-44422

An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before 2022.12. Crafted data in a B…

Fix: 2022.12+
Fix from $1,950 2021-12-21
Parquet Java HIGH 7.5
CVE-2021-41561

Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apac…

Fix: 1.11.2 / 1.12.2+
Fix from $1,950 2021-12-20
Log4j MEDIUM 5.9
CVE-2021-45105EPSS 100%

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential looku…

Fix: 2.3.1 / 2.7.0+
Fix from $1,600 2021-12-18