Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Maepsbroker CRITICAL 9.8
CVE-2020-7839

In MaEPSBroker 2.5.0.31 and prior, a command injection vulnerability caused by improper input validation checks when parsing brokerCommand parameter.

Fix: after 2.5.0.31
Fix from $2,300 2021-03-24
Keycloak HIGH 7.5
CVE-2021-20222

A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat …

Fix: 13.0.0+
Fix from $1,950 2021-03-23
TYPO3 HIGH 8.3
CVE-2021-21357

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input valid…

Fix: 8.7.40 / 9.5.25+
Fix from $1,950 2021-03-23
Schema Inspector HIGH 7.5
CVE-2021-21267

Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address va…

Fix: 2.0.0+
Fix from $1,950 2021-03-19
Debian Linux HIGH 8.6
CVE-2020-25097EPSS 8%

An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Req…

Fix: 4.14 / 5.0.5+
Fix from $1,950 2021-03-19
Office MEDIUM 6.5
CVE-2021-20631

Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App…

Fix: after 10.8.4
Fix from $1,600 2021-03-18
Connect HIGH 7.8
CVE-2021-21085

Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vul…

Fix: after 11.0.7
Fix from $1,950 2021-03-12
Creative Cloud Desktop Application HIGH 7.8
CVE-2021-21069

Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an atta…

Fix: after 5.3
Fix from $1,950 2021-03-12
Android MEDIUM 5.5
CVE-2021-0377

In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a loc…

Mitigation only
Fix from $1,600 2021-03-10
Growi HIGH 7.2
CVE-2021-20671

Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files …

Mitigation only
Fix from $1,950 2021-03-10
Linux Kernel HIGH 7.8
CVE-2021-20268

An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls…

Fix: 5.10.10+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20273

A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Idrac8 Firmware MEDIUM 6.1
CVE-2021-21510

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit th…

Fix: 2.75.100.75+
Fix from $1,600 2021-03-08
Emc Powerscale Onefs HIGH 8.8
CVE-2021-21506

PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPO…

Mitigation only
Fix from $1,950 2021-03-08
Cyclonetcp HIGH 7.5
CVE-2021-26788

Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exp…

Fix: after 2.0.0
Fix from $1,950 2021-03-08
Gatemanager Firmware MEDIUM 6.1
CVE-2020-29029

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascr…

Fix: 9.4.62105402+
Fix from $1,600 2021-03-05
Android MEDIUM 5.5
CVE-2021-25334

Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent d…

Mitigation only
Fix from $1,600 2021-03-04
Android MEDIUM 5.2
CVE-2021-25338

Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to wr…

Mitigation only
Fix from $1,600 2021-03-04
Android MEDIUM 5.2
CVE-2021-25339

Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corr…

Mitigation only
Fix from $1,600 2021-03-04
Joomla\! HIGH 7.5
CVE-2021-23131

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.

Fix: 3.9.25+
Fix from $1,950 2021-03-04
View Planner CRITICAL 9.8
CVE-2021-21978EPSS 99%

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza…

Fix: 4.6+
Fix from $2,300 2021-03-03
Fedora MEDIUM 6.5
CVE-2020-28591

An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 9…

No fix yet
Fix from $1,600 2021-03-03
Pillow HIGH 7.5
CVE-2021-27921

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly…

Fix: 8.1.1+
Fix from $1,950 2021-03-03
Pillow HIGH 7.5
CVE-2021-27922

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly…

Fix: 8.1.1+
Fix from $1,950 2021-03-03
Pillow HIGH 7.5
CVE-2021-27923

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly…

Fix: 8.1.1+
Fix from $1,950 2021-03-03
Fastify Reply From CRITICAL 10.0
CVE-2021-21321

fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before ve…

Fix: 4.0.2+
Fix from $2,300 2021-03-02
Fastify Http Proxy CRITICAL 9.8
CVE-2021-21322

fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific …

Fix: 4.3.1+
Fix from $2,300 2021-03-02
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2021-1450

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attack…

Mitigation only
Fix from $1,600 2021-02-24
Batik HIGH 8.2
CVE-2020-11987EPSS 14%

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf…

Fix: after 1.13
Fix from $1,950 2021-02-24
Xmlgraphics Commons HIGH 8.2
CVE-2020-11988EPSS 7%

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi…

Fix: after 2.4
Fix from $1,950 2021-02-24