Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Simatic Rtls Locating Manager HIGH 7.2
CVE-2025-40746

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a ba…

Fix: 3.2+
Fix from $1,950 2025-08-12
Openharmony MEDIUM 5.5
CVE-2025-25212

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.

Fix: after 5.0.3
Fix from $1,600 2025-08-11
Learning HIGH 8.8
CVE-2025-55006

Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not a…

Fix: 2.34.0+
Fix from $1,950 2025-08-09
Cxf CRITICAL 9.8
CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…

Fix: 3.6.8 / 4.0.9+
Fix from $2,300 2025-08-08
White Jotter HIGH 7.5
CVE-2025-8708

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeMan…

No fix yet
Fix from $1,950 2025-08-08
Unclassified MEDIUM 6.8
CVE-2025-54368

uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, …

Patch available
Fix from $1,600 2025-08-08
Ollama MEDIUM 6.6
CVE-2025-44779

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

Mitigation only
Fix from $1,600 2025-08-07
Suitecrm HIGH 8.8
CVE-2025-54785

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplie…

Mitigation only
Fix from $1,950 2025-08-07
Qcms MEDIUM 6.5
CVE-2025-50233

A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name"…

No fix yet
Fix from $1,600 2025-08-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2025-21477

Transient DOS while processing CCCH data when NW sends data with invalid length.

Mitigation only
Fix from $1,950 2025-08-06
Emui MEDIUM 5.5
CVE-2025-54642

Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerabili…

Mitigation only
Fix from $1,600 2025-08-06
Emui MEDIUM 5.5
CVE-2025-54641

Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerab…

No fix yet
Fix from $1,600 2025-08-06
Emui MEDIUM 5.5
CVE-2025-54636

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulner…

No fix yet
Fix from $1,600 2025-08-06
Harmonyos MEDIUM 5.5
CVE-2025-54614

Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-08-06
Unclassified HIGH 7.1
CVE-2025-7674

Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denia…

Mitigation only
Fix from $1,950 2025-08-05
Unclassified HIGH 7.5
CVE-2025-27211

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to E…

Mitigation only
Fix from $1,950 2025-08-04
Unclassified CRITICAL 9.8
CVE-2025-27212

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access managem…

Mitigation only
Fix from $2,300 2025-08-04
Zeppelin MEDIUM 5.3
CVE-2024-52279

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. …

Fix: 0.12.0+
Fix from $1,600 2025-08-03
Unclassified HIGH 7.8
CVE-2025-54564

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the no…

Mitigation only
Fix from $1,950 2025-08-01
Unclassified HIGH 8.6
CVE-2011-10008

A stack-based buffer overflow vulnerability exists in MPlayer Lite r33064 due to improper bounds checking when handling M3U playlist files containing…

No fix yet
Fix from $1,950 2025-07-31
Powerprotect Data Manager MEDIUM 6.5
CVE-2025-30480

Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager. A low pr…

Fix: 19.20+
Fix from $1,600 2025-07-30
Docker Heimdall CRITICAL 9.8
CVE-2025-50578

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Refer…

Mitigation only
Fix from $2,300 2025-07-30
Unclassified MEDIUM 6.0
CVE-2025-4424

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" w…

No fix yet
Fix from $1,600 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43253

This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able …

Fix: 14.7.7 / 15.6+
Fix from $2,300 2025-07-30
Ipados CRITICAL 9.8
CVE-2025-43234

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6,…

Fix: 2.6 / 11.6+
Fix from $2,300 2025-07-30
Ipados HIGH 7.5
CVE-2025-43223

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia…

Fix: 2.6 / 11.6+
Fix from $1,950 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43195

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15…

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-07-30
Ipados CRITICAL 9.1
CVE-2025-31281

An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6…

Fix: 2.6 / 15.6+
Fix from $2,300 2025-07-30
E Diary Management System HIGH 7.5
CVE-2025-50492

Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a ses…

Mitigation only
Fix from $1,950 2025-07-28
Student Result Management System HIGH 7.5
CVE-2025-50489

Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to exec…

No fix yet
Fix from $1,950 2025-07-28