Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 5.1
CVE-2025-53471

Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are require…

No fix yet
Fix from $1,600 2025-07-11
Unclassified CRITICAL 9.3
CVE-2025-34102EPSS 7%

A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and c…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34099

An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php compone…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34100

An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuer…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34101

An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoi…

No fix yet
Fix from $2,300 2025-07-10
HTTP Server HIGH 7.5
CVE-2024-42516

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
Arena HIGH 7.8
CVE-2025-6376

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the b…

Fix: 16.20.09+
Fix from $1,950 2025-07-09
Arena HIGH 7.8
CVE-2025-6377

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the b…

Fix: 16.20.09+
Fix from $1,950 2025-07-09
Git Parameter HIGH 8.2
CVE-2025-53652

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the…

Fix: 444.vca_b_84d3703c2+
Fix from $1,950 2025-07-09
Rtl8762e Software Development Kit MEDIUM 6.5
CVE-2025-44526

Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (B…

No fix yet
Fix from $1,600 2025-07-09
Unclassified MEDIUM 6.0
CVE-2025-7378

An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lea…

Mitigation only
Fix from $1,600 2025-07-09
Unclassified HIGH 7.3
CVE-2025-7216

A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /app…

Mitigation only
Fix from $1,950 2025-07-09
Sql Server 2016 HIGH 7.5
CVE-2025-49719EPSS 11%

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

Fix: 13.0.6460.7 / 13.0.7055.9+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-47982

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Simatic Cn 4100 Firmware MEDIUM 6.5
CVE-2025-40593

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitr…

Fix: 4.0+
Fix from $1,600 2025-07-08
Charx Sec 3000 Firmware HIGH 7.8
CVE-2025-24005

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware MEDIUM 5.3
CVE-2025-24002

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in …

Fix: after 1.6.5
Fix from $1,600 2025-07-08
Exynos 2400 Firmware HIGH 7.5
CVE-2025-26780

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Servi…

Mitigation only
Fix from $1,950 2025-07-07
Boyuncms MEDIUM 5.9
CVE-2025-7099

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality …

Fix: after 1.21
Fix from $1,600 2025-07-07
Monitorr HIGH 8.1
CVE-2025-7060

A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_in…

Fix: after 1.7.6m
Fix from $1,950 2025-07-04
Unclassified MEDIUM 6.5
CVE-2025-53502

Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Scripting (XSS).This issue affe…

Mitigation only
Fix from $1,600 2025-07-03
Unclassified MEDIUM 6.5
CVE-2025-52891

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an…

Patch available
Fix from $1,600 2025-07-02
Unclassified CRITICAL 9.3
CVE-2025-34072

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI…

Mitigation only
Fix from $2,300 2025-07-02
G42 Firmware MEDIUM 6.5
CVE-2025-27023

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via cr…

Fix: 7.1+
Fix from $1,600 2025-07-02
Unclassified CRITICAL 9.4
CVE-2025-34055

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the A…

No fix yet
Fix from $2,300 2025-07-01
Unclassified CRITICAL 9.4
CVE-2025-34056

An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group mana…

No fix yet
Fix from $2,300 2025-07-01
Unclassified CRITICAL 10.0
CVE-2025-34060

A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the …

Mitigation only
Fix from $2,300 2025-07-01
Rlottie CRITICAL 9.8
CVE-2025-53076

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

Patch available
Fix from $2,300 2025-06-30
Rlottie CRITICAL 9.8
CVE-2025-53075

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

Patch available
Fix from $2,300 2025-06-30
Unclassified HIGH 7.3
CVE-2025-5878

A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL …

Patch available
Fix from $1,950 2025-06-29