Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android MEDIUM 6.7
CVE-2021-25503

Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

Mitigation only
Fix from $1,600 2021-11-05
Ios Xr HIGH 7.2
CVE-2021-40120

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…

Mitigation only
Fix from $1,950 2021-11-04
Sf200 24 Firmware MEDIUM 5.3
CVE-2021-40127

A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Swit…

Mitigation only
Fix from $1,600 2021-11-04
Pc Worx HIGH 7.8
CVE-2021-34597

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated …

Fix: after 1.88
Fix from $1,950 2021-11-04
Traffic Server HIGH 7.5
CVE-2021-37148

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.0.1
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37149

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-41585

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting…

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Traffic Server HIGH 7.5
CVE-2021-37147

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache …

Fix: after 9.1.0
Fix from $1,950 2021-11-03
Clusterpro X HIGH 7.5
CVE-2021-20705

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLU…

Fix: after 4.3
Fix from $1,950 2021-11-03
Clusterpro X HIGH 7.5
CVE-2021-20706

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLU…

Fix: after 4.3
Fix from $1,950 2021-11-03
Clusterpro X HIGH 7.5
CVE-2021-20707

Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earl…

Fix: after 4.3
Fix from $1,950 2021-11-03
Linux Kernel HIGH 8.8
CVE-2017-5123

Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.

Fix: 4.13.7+
Fix from $1,950 2021-11-02
Chrome MEDIUM 5.5
CVE-2021-37996

Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictio…

Fix: 95.0.4638.54+
Fix from $1,600 2021-11-02
Ingress Nginx HIGH 7.1
CVE-2021-25742

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain…

Fix: 0.49.1+
Fix from $1,950 2021-10-29
Emui HIGH 7.5
CVE-2021-22491

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

No fix yet
Fix from $1,950 2021-10-28
Harmonyos MEDIUM 5.5
CVE-2021-22467

A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.

Mitigation only
Fix from $1,600 2021-10-28
Harmonyos MEDIUM 5.5
CVE-2021-22452

A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.

Mitigation only
Fix from $1,600 2021-10-28
Secure Firewall Threat Defense HIGH 7.5
CVE-2021-34783

A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) …

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,950 2021-10-27
Adaptive Security Appliance MEDIUM 5.3
CVE-2021-34790

Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Applianc…

Fix: 6.4.0.12 / 6.6.5+
Fix from $1,600 2021-10-27
Adaptive Security Appliance MEDIUM 5.3
CVE-2021-34791

Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Applianc…

Fix: 6.4.0.12 / 6.6.5+
Fix from $1,600 2021-10-27
Firepower Management Center Virtual Appliance HIGH 7.8
CVE-2021-34755

Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrar…

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,950 2021-10-27
Firepower Management Center Virtual Appliance HIGH 7.8
CVE-2021-34756

Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrar…

Fix: 6.4.0.13 / 6.6.5+
Fix from $1,950 2021-10-27
Helpuviewer HIGH 7.8
CVE-2020-7867

An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file…

Mitigation only
Fix from $1,950 2021-10-27
Calibre CRITICAL 9.8
CVE-2011-4124

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

No fix yet
Fix from $2,300 2021-10-27
Go Ethereum MEDIUM 5.7
CVE-2021-41173

Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node is susceptible to crash when p…

Fix: 1.10.9+
Fix from $1,600 2021-10-26
Nexacro CRITICAL 9.8
CVE-2021-26607

An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.

Fix: after 17.1.3.301
Fix from $2,300 2021-10-26
Freeswitch HIGH 7.5
CVE-2021-41105

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.7+
Fix from $1,950 2021-10-25
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-38485

The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to re…

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Android MEDIUM 5.5
CVE-2021-0651

In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. Thi…

Mitigation only
Fix from $1,600 2021-10-22
Versiondog MEDIUM 6.5
CVE-2021-38455

The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls wit…

Fix: 8.0.0+
Fix from $1,600 2021-10-22