Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Jdbc Driver For Sql Server HIGH 8.1
CVE-2025-59250

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.2.4 / 11.2.4+
Fix from $1,950 2025-10-14
Exchange Server HIGH 7.5
CVE-2025-59248

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 15.02.2562.029+
Fix from $1,950 2025-10-14
Sharepoint Server HIGH 8.8
CVE-2025-59228

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19127.20262+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-59207

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.0
CVE-2025-59198

Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59187

Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59190

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 8.8
CVE-2025-58716

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-55692

Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Unclassified HIGH 8.7
CVE-2025-9066

A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused…

Mitigation only
Fix from $1,950 2025-10-14
Unclassified HIGH 7.5
CVE-2011-20001

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (…

Mitigation only
Fix from $1,950 2025-10-14
Unclassified HIGH 7.5
CVE-2025-62162

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malform…

Mitigation only
Fix from $1,950 2025-10-10
Authlib HIGH 7.5
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JW…

Fix: 1.6.5+
Fix from $1,950 2025-10-10
Csr8811 Firmware MEDIUM 6.5
CVE-2025-27040

Information disclosure may occur while processing the hypervisor log.

No fix yet
Fix from $1,600 2025-10-09
Unclassified MEDIUM 5.1
CVE-2025-61768

KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists i…

Patch available
Fix from $1,600 2025-10-06
Ilias CRITICAL 9.8
CVE-2025-11346

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such ma…

Mitigation only
Fix from $2,300 2025-10-06
Ilias CRITICAL 9.8
CVE-2025-11345

A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulati…

Mitigation only
Fix from $2,300 2025-10-06
Unclassified MEDIUM 6.3
CVE-2025-11273

A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oa…

Mitigation only
Fix from $1,600 2025-10-04
Motioneye HIGH 7.2
CVE-2025-60787EPSS 18%

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is w…

No fix yet
Fix from $1,950 2025-10-03
Unclassified HIGH 7.1
CVE-2025-34226

OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is …

Patch available
Fix from $1,950 2025-10-03
Ts3 Manager HIGH 7.5
CVE-2025-61582

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and e…

Fix: 2.2.2+
Fix from $1,950 2025-10-01
Ts3 Manager MEDIUM 6.1
CVE-2025-61583

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in version…

Fix: 2.2.2+
Fix from $1,600 2025-10-01
Argo Cd HIGH 7.5
CVE-2025-59537

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through …

Fix: 2.14.20 / 3.0.19+
Fix from $1,950 2025-10-01
Unclassified HIGH 7.0
CVE-2025-11226

ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allow…

Mitigation only
Fix from $1,950 2025-10-01
Unclassified HIGH 8.7
CVE-2025-59952

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service…

Patch available
Fix from $1,950 2025-09-30
Unclassified MEDIUM 6.5
CVE-2025-59940

mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input c…

Patch available
Fix from $1,600 2025-09-29
Unclassified HIGH 7.3
CVE-2025-11135

A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the func…

Mitigation only
Fix from $1,950 2025-09-29
Unclassified MEDIUM 6.3
CVE-2025-10975

A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.rob…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified MEDIUM 6.3
CVE-2025-10974

A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of th…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified MEDIUM 6.3
CVE-2025-10965

A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/co…

Mitigation only
Fix from $1,600 2025-09-25