Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Mattermost Server MEDIUM 5.7
CVE-2021-37863

Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-sid…

Fix: after 6.0
Fix from $1,600 2021-12-17
Android HIGH 7.3
CVE-2021-1021

In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper in…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.3
CVE-2021-1020

In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper inpu…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0921

In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation.…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0928

In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. …

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 8.0
CVE-2021-0933

In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog d…

Mitigation only
Fix from $1,950 2021-12-15
MongoDB MEDIUM 6.5
CVE-2021-20330

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in …

Fix: 4.0.25 / 4.2.14+
Fix from $1,600 2021-12-15
Jetengine CRITICAL 9.8
CVE-2021-41844

Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.

Fix: 2.9.1+
Fix from $2,300 2021-12-15
Kyma HIGH 8.8
CVE-2021-38182

Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely comp…

Fix: 1.24.7+
Fix from $1,950 2021-12-14
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Next.js HIGH 7.5
CVE-2021-43803EPSS 45%

Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to b…

Fix: 11.1.3 / 12.0.5+
Fix from $1,950 2021-12-10
Etherpad HIGH 8.8
CVE-2021-43802

Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allo…

Fix: 1.8.16+
Fix from $1,950 2021-12-09
Bosch Video Management System HIGH 7.2
CVE-2021-23862

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue a…

Fix: 10.0.2+
Fix from $1,950 2021-12-08
Harmonyos MEDIUM 6.5
CVE-2021-37039

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Bluetooth DoS.

Fix: 2.0+
Fix from $1,600 2021-12-08
Android HIGH 7.8
CVE-2021-25517

An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.

Mitigation only
Fix from $1,950 2021-12-08
Internet MEDIUM 6.1
CVE-2021-25520

Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applica…

Fix: 16.0.2+
Fix from $1,600 2021-12-08
Android HIGH 7.8
CVE-2021-25510

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

Mitigation only
Fix from $1,950 2021-12-08
Android HIGH 7.8
CVE-2021-25511

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal…

Mitigation only
Fix from $1,950 2021-12-08
Android HIGH 7.8
CVE-2021-25512

An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $1,950 2021-12-08
Harmonyos HIGH 7.5
CVE-2021-37081

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to nearby crash.

Fix: 2.0+
Fix from $1,950 2021-12-07
Harmonyos CRITICAL 9.8
CVE-2021-37084

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking …

Fix: 2.0+
Fix from $2,300 2021-12-07
Harmonyos HIGH 7.5
CVE-2021-37094

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of se…

Fix: 2.0+
Fix from $1,950 2021-12-07
Harmonyos HIGH 7.5
CVE-2021-37096

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclo…

Fix: 2.0+
Fix from $1,950 2021-12-07
Harmonyos HIGH 7.5
CVE-2021-37048

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to fake visitors to co…

Fix: 2.0+
Fix from $1,950 2021-12-07
Harmonyos HIGH 7.5
CVE-2021-37060

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to SAMGR Heap Address …

Fix: 2.0+
Fix from $1,950 2021-12-07
Emui HIGH 7.5
CVE-2021-37047

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause some services to restart.

No fix yet
Fix from $1,950 2021-12-07
Melsec Iq R R00 Cpu Firmware HIGH 7.5
CVE-2021-20611

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ…

Fix: after 57
Fix from $1,950 2021-12-01
Neors HIGH 8.8
CVE-2020-7880

The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execu…

Mitigation only
Fix from $1,950 2021-11-30
Nexacro CRITICAL 9.8
CVE-2021-26612

An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method t…

Fix: after 17.1.2.500
Fix from $2,300 2021-11-30
Topease MEDIUM 5.4
CVE-2021-42117

Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authentica…

Fix: after 7.1.27
Fix from $1,600 2021-11-30