Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Experience Manager HIGH 7.7
CVE-2025-54248EPSS 5%

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security fea…

Fix: after 2025.8.0
Fix from $1,950 2025-09-09
Windows 11 24h2 MEDIUM 6.5
CVE-2025-53809

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Fix: 10.0.26100.6508+
Fix from $1,600 2025-09-09
Commerce CRITICAL 9.1
CVE-2025-54236 KEVEPSS 95%

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vu…

Mitigation only
Fix from $2,300 2025-09-09
1756 En2tr Series A Firmware MEDIUM 6.5
CVE-2025-8007

A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trig…

Fix: 7.001+
Fix from $1,600 2025-09-09
MongoDB MEDIUM 6.5
CVE-2025-10061

An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect h…

Fix: 6.0.25 / 7.0.22+
Fix from $1,600 2025-09-05
Unclassified HIGH 8.2
CVE-2025-58353

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio…

Mitigation only
Fix from $1,950 2025-09-04
Unclassified CRITICAL 9.3
CVE-2025-58361

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive U…

Mitigation only
Fix from $2,300 2025-09-04
Android HIGH 7.8
CVE-2025-32322

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recordi…

Mitigation only
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-48559

In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to l…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.3
CVE-2025-48556

In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. This could …

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-48538

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input v…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-48541

In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This coul…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.1
CVE-2025-48537

In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32323

In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26429

In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.1
CVE-2025-26426

In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due t…

Mitigation only
Fix from $1,600 2025-09-04
Unclassified MEDIUM 5.3
CVE-2025-9467

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Use…

Mitigation only
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2024-56190

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escal…

Mitigation only
Fix from $1,950 2025-09-04
Dolphinscheduler HIGH 8.8
CVE-2024-43115

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This…

Fix: 3.2.2+
Fix from $1,950 2025-09-03
Android MEDIUM 6.8
CVE-2023-21472

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in …

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 6.8
CVE-2023-21473

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in …

Mitigation only
Fix from $1,600 2025-09-03
Silverpeas MEDIUM 6.5
CVE-2025-46047

A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin…

Patch available
Fix from $1,600 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.5
CVE-2025-52547

E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to con…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
E3 Supervisory Controller Firmware HIGH 7.5
CVE-2025-52544

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan fil…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
Ac10 Firmware MEDIUM 5.3
CVE-2025-57220

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP p…

Mitigation only
Fix from $1,600 2025-08-28
O2oa HIGH 8.8
CVE-2024-37777

O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.

No fix yet
Fix from $1,950 2025-08-27
Coolify HIGH 8.8
CVE-2025-34159

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platf…

Fix: 4.0.0+
Fix from $1,950 2025-08-27
Coolify HIGH 8.8
CVE-2025-34161

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform …

Fix: 4.0.0+
Fix from $1,950 2025-08-27
Coolify CRITICAL 9.0
CVE-2025-34157

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authent…

Fix: 4.0.0+
Fix from $2,300 2025-08-27
Jspdf HIGH 7.5
CVE-2025-57810

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilizati…

Fix: 3.0.2+
Fix from $1,950 2025-08-26