Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Digital Employee Experience MEDIUM 6.5
CVE-2025-12687

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows m…

Fix: 25.11+
Fix from $1,600 2025-12-11
Coldfusion MEDIUM 6.2
CVE-2025-61822

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file…

Mitigation only
Fix from $1,600 2025-12-10
Coldfusion CRITICAL 9.1
CVE-2025-61809

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security f…

Mitigation only
Fix from $2,300 2025-12-10
Coldfusion HIGH 8.4
CVE-2025-61812

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privilege…

Mitigation only
Fix from $1,950 2025-12-10
Exchange Server HIGH 7.5
CVE-2025-64666

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Fix: 15.02.2562.035+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62571

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62455

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
R7000p Firmware HIGH 7.2
CVE-2025-12945

A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. T…

Fix: after 1.3.3.154
Fix from $1,950 2025-12-09
Rs700 Firmware HIGH 7.5
CVE-2025-12946

A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the route…

Fix: 1.0.9.6 / 1.0.17.142+
Fix from $1,950 2025-12-09
Sinec Security Monitor MEDIUM 6.5
CVE-2025-40831

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date param…

Fix: 4.10.0+
Fix from $1,600 2025-12-09
Unclassified HIGH 8.4
CVE-2025-2296

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulne…

Mitigation only
Fix from $1,950 2025-12-09
Security Operations Soar HIGH 7.2
CVE-2025-13428

A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote …

Fix: 6.3.64+
Fix from $1,950 2025-12-09
Android HIGH 7.8
CVE-2025-48632

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due …

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48638

In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48623

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48624

In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation…

Mitigation only
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48601

In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48612

In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.3
CVE-2025-48594

In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to im…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48525

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a compan…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48566

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead …

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 6.7
CVE-2025-22432

In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to loc…

Patch available
Fix from $1,600 2025-12-08
Infinera Mtc 9 Firmware HIGH 7.5
CVE-2025-26488

Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the applian…

Fix: 23.0+
Fix from $1,950 2025-12-08
Infinera Mtc 9 Firmware MEDIUM 6.5
CVE-2025-26489

Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, …

Fix: 23.0+
Fix from $1,600 2025-12-08
Torrent Suite Software HIGH 7.2
CVE-2025-54306

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network con…

Mitigation only
Fix from $1,950 2025-12-04
Unclassified HIGH 7.5
CVE-2024-3884

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSource…

Mitigation only
Fix from $1,950 2025-12-03
Splunk MEDIUM 6.5
CVE-2025-20389

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app o…

Fix: 3.7.28 / 3.8.58+
Fix from $1,600 2025-12-03
Mdast Util To Hast MEDIUM 5.3
CVE-2025-66400

mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdow…

Fix: 13.2.1+
Fix from $1,600 2025-12-01
Hello Video Codec MEDIUM 6.5
CVE-2025-63095

Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of S…

Patch available
Fix from $1,600 2025-12-01
Diris M 70 Firmware HIGH 7.5
CVE-2025-26858

A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted set of network packe…

Mitigation only
Fix from $1,950 2025-12-01