Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux HIGH 7.8
CVE-2021-36048

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execut…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 7.2
CVE-2021-36025

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 7.5
CVE-2021-36030

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 8.8
CVE-2021-36032

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 7.2
CVE-2021-36034

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 7.2
CVE-2021-36035

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce MEDIUM 6.5
CVE-2021-36038

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,600 2021-09-01
Iportalis Control Portal HIGH 7.5
CVE-2020-9002

An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN t…

Mitigation only
Fix from $1,950 2021-09-01
Serv U HIGH 8.8
CVE-2021-35223

The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with paramete…

Fix: 15.2.4+
Fix from $1,950 2021-08-31
Magento HIGH 7.2
CVE-2021-32759

OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 2…

Fix: 19.4.13 / 20.0.11+
Fix from $1,950 2021-08-27
Nx Os HIGH 8.6
CVE-2021-1588

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote a…

Patch available
Fix from $1,950 2021-08-25
Ipad Os HIGH 7.8
CVE-2021-30917

A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation. This issue is fixed in …

Fix: 8.1 / 10.15.7+
Fix from $1,950 2021-08-24
Ipados HIGH 7.8
CVE-2021-30881

An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 1…

Fix: 8.1 / 10.15.7+
Fix from $1,950 2021-08-24
Itunes U MEDIUM 6.1
CVE-2021-30862

A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may le…

Fix: 3.8.3+
Fix from $1,600 2021-08-24
S12700 Firmware HIGH 7.5
CVE-2021-22357

There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages due to validating inputs insufficiently. A…

Mitigation only
Fix from $1,950 2021-08-23
Nichestack HIGH 7.5
CVE-2020-35684

An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from t…

Fix: 1.2.0 / 2.0.0+
Fix from $1,950 2021-08-19
Nichestack HIGH 7.5
CVE-2021-31401

An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP…

Fix: 1.2.0 / 2.0.0+
Fix from $1,950 2021-08-19
Android MEDIUM 5.5
CVE-2021-0416

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0417

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0418

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0419

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no ad…

Mitigation only
Fix from $1,600 2021-08-18
Garoon MEDIUM 5.3
CVE-2021-20764

Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Fi…

Fix: after 5.0.2
Fix from $1,600 2021-08-18
Shopware HIGH 7.5
CVE-2021-37707

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulation of product reviews via API.…

Fix: 6.4.3.1+
Fix from $1,950 2021-08-16
Node.js CRITICAL 9.8
CVE-2021-22931EPSS 22%

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host …

Fix: 12.22.5 / 14.17.5+
Fix from $2,300 2021-08-16
Tensorflow MEDIUM 5.5
CVE-2021-37677

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has …

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37692

TensorFlow is an end-to-end open source platform for machine learning. In affected versions under certain conditions, Go code can trigger a segfault …

Fix: 2.6.0+
Fix from $1,600 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37663

TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in `tf.raw_ops.QuantizeV2`, …

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37665

TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation in MKL implementation of req…

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37673

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a `CHECK`…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37674

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segment…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12