Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Expressionengine CRITICAL 9.8
CVE-2021-33199

In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fix…

Fix: 6.0.3+
Fix from $2,300 2021-08-12
Application Insight Manager HIGH 8.1
CVE-2021-36982

AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allows OS Command Injection becau…

Mitigation only
Fix from $1,950 2021-08-12
Jetson Linux HIGH 7.1
CVE-2021-1110

NVIDIA Linux kernel distributions on Jetson Xavier contain a vulnerability in camera firmware where a user can change input data after validation, wh…

Fix: 32.6.1+
Fix from $1,950 2021-08-11
Pan Os MEDIUM 5.9
CVE-2021-3048

Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition c…

Fix: 9.0.14 / 9.1.9+
Fix from $1,600 2021-08-11
Graphics Drivers HIGH 7.8
CVE-2021-0062

Improper input validation in some Intel(R) Graphics Drivers before version 27.20.100.8935 may allow an authenticated user to potentially enable escal…

Fix: 27.20.100.8935+
Fix from $1,950 2021-08-11
Ethernet Controller E810 Firmware HIGH 7.8
CVE-2021-0084

Improper input validation in the Intel(R) Ethernet Controllers X722 and 800 series Linux RMDA driver before version 1.3.19 may allow an authenticated…

Fix: 1.3.19 / 1.4.11+
Fix from $1,950 2021-08-11
Kyma HIGH 8.8
CVE-2021-33708

Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges.

Fix: 1.24+
Fix from $1,950 2021-08-10
Content Navigator MEDIUM 6.5
CVE-2021-29714

IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.

Mitigation only
Fix from $1,600 2021-08-09
Magicline4nx.exe CRITICAL 9.8
CVE-2021-26606

A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validat…

Fix: after 1.0.0.17
Fix from $2,300 2021-08-06
Enterprise Linux HIGH 7.5
CVE-2021-3580

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a mani…

Fix: 3.7.3+
Fix from $1,950 2021-08-05
Ezpdfreader CRITICAL 9.8
CVE-2021-26605

An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the e…

Fix: after 3.0
Fix from $2,300 2021-08-05
Raon K Upload HIGH 8.8
CVE-2020-7863

A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. T…

Fix: 2018.0.2.56+
Fix from $1,950 2021-08-05
Android MEDIUM 5.5
CVE-2021-25444

An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.

Mitigation only
Fix from $1,600 2021-08-05
Small Business Rv Series Router Firmware CRITICAL 9.8
CVE-2021-1602

A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an una…

Fix: 1.0.01.04+
Fix from $2,300 2021-08-04
Oxfords An00a Firmware MEDIUM 5.5
CVE-2021-22400

Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into…

Mitigation only
Fix from $1,600 2021-08-03
Argo Workflows MEDIUM 6.5
CVE-2021-37914

In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflow…

Fix: after 3.1.3
Fix from $1,600 2021-08-03
Fedora HIGH 7.5
CVE-2021-3673

A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and…

Patch available
Fix from $1,950 2021-08-02
Go HIGH 7.5
CVE-2021-33196

In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.

Fix: 1.15.13 / 1.16.5+
Fix from $1,950 2021-08-02
Emui HIGH 7.5
CVE-2021-22445

There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.

No fix yet
Fix from $1,950 2021-08-02
Manageone MEDIUM 6.7
CVE-2021-22397

There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be …

No fix yet
Fix from $1,600 2021-08-02
Emui HIGH 7.5
CVE-2021-22443

There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause random address access.

Mitigation only
Fix from $1,950 2021-08-02
Emui CRITICAL 9.8
CVE-2021-22444

There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause code injection.

No fix yet
Fix from $2,300 2021-08-02
Emui HIGH 7.5
CVE-2021-22381

There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause an infinite loop in DoS.

Mitigation only
Fix from $1,950 2021-08-02
Mbdialup CRITICAL 9.8
CVE-2021-33527

In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORI…

Fix: after 3.9r0.0
Fix from $2,300 2021-08-02
Proficy Machine Edition MEDIUM 5.3
CVE-2021-29298

Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash…

Mitigation only
Fix from $1,600 2021-07-30
Freerdp CRITICAL 9.8
CVE-2021-37594

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENT…

Fix: 2.4.0+
Fix from $2,300 2021-07-30
Freerdp CRITICAL 9.8
CVE-2021-37595

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENT…

Fix: 2.4.0+
Fix from $2,300 2021-07-30
Officescan HIGH 7.8
CVE-2021-36742 KEV

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 all…

Mitigation only
Fix from $1,950 2021-07-29
Mosquitto HIGH 7.5
CVE-2021-34432

In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.

Fix: after 2.0.7
Fix from $1,950 2021-07-27
Archisteamfarm MEDIUM 5.9
CVE-2021-32795

ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In versions prior to 4.3.1.0 a D…

Fix: 4.3.1.0+
Fix from $1,600 2021-07-26