Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 6.5
CVE-2023-28911

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied dat…

Mitigation only
Fix from $1,600 2025-06-28
Unclassified HIGH 8.7
CVE-2025-34047

A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files o…

Mitigation only
Fix from $1,950 2025-06-26
Unclassified CRITICAL 10.0
CVE-2025-34043EPSS 8%

A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.c…

Mitigation only
Fix from $2,300 2025-06-26
MongoDB HIGH 7.5
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC…

Fix: 6.0.21 / 7.0.17+
Fix from $1,950 2025-06-26
Neqo MEDIUM 6.5
CVE-2025-6703

Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.

Fix: after 0.13.2
Fix from $1,600 2025-06-26
Servicestack MEDIUM 5.9
CVE-2025-6444

ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attackers to relay NTLM credential…

Fix: 8.6+
Fix from $1,600 2025-06-25
Openbao HIGH 7.5
CVE-2025-52894

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao befo…

Fix: 2.3.0+
Fix from $1,950 2025-06-25
Unclassified MEDIUM 6.6
CVE-2025-52569

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-prov…

Patch available
Fix from $1,600 2025-06-25
Unclassified MEDIUM 6.6
CVE-2025-50178

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certa…

Patch available
Fix from $1,600 2025-06-25
Unclassified HIGH 8.8
CVE-2025-52568

NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory cor…

Patch available
Fix from $1,950 2025-06-24
Unclassified CRITICAL 9.1
CVE-2025-6545

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program fil…

Patch available
Fix from $2,300 2025-06-23
Unclassified CRITICAL 9.1
CVE-2025-6547

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.

Patch available
Fix from $2,300 2025-06-23
Unclassified HIGH 7.8
CVE-2025-34021

A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, T…

No fix yet
Fix from $1,950 2025-06-20
Upsonic HIGH 8.0
CVE-2025-6279

A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the f…

Fix: after 0.55.6
Fix from $1,950 2025-06-19
Open5gs HIGH 7.1
CVE-2025-29646

An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest pac…

Fix: after 2.7.2
Fix from $1,950 2025-06-18
Insydeh2o MEDIUM 6.7
CVE-2024-55567

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and …

Fix: 5.4.05.47.01 / 5.5.05.55.01+
Fix from $1,600 2025-06-12
Web Designer HIGH 8.8
CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…

Fix: 16.3.0.0407+
Fix from $1,950 2025-06-12
Unclassified CRITICAL 9.5
CVE-2024-1244

Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in p…

Mitigation only
Fix from $2,300 2025-06-11
Wazuh HIGH 7.2
CVE-2024-1243

Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to…

Fix: 4.8.0+
Fix from $1,950 2025-06-11
Unclassified HIGH 8.7
CVE-2025-0051

Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.

Mitigation only
Fix from $1,950 2025-06-10
Unclassified HIGH 8.3
CVE-2025-0052

Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.

Mitigation only
Fix from $1,950 2025-06-10
Autoupdate HIGH 7.8
CVE-2025-47968

Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.79+
Fix from $1,950 2025-06-10
365 Apps MEDIUM 6.7
CVE-2025-47171

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

Mitigation only
Fix from $1,600 2025-06-10
Unclassified MEDIUM 6.5
CVE-2025-3898

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request co…

Mitigation only
Fix from $1,600 2025-06-10
Unclassified HIGH 8.6
CVE-2025-4680

Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified MEDIUM 6.5
CVE-2025-3116

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malforme…

No fix yet
Fix from $1,600 2025-06-10
Call Management System CRITICAL 9.8
CVE-2025-1041

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web re…

Fix: 19.2.0.7 / 20.0.1.0+
Fix from $2,300 2025-06-10
Unclassified MEDIUM 6.6
CVE-2025-0037

In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to i…

No fix yet
Fix from $1,600 2025-06-10
Openharmony MEDIUM 5.5
CVE-2025-27131

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

Fix: after 5.0.3
Fix from $1,600 2025-06-08
Openharmony MEDIUM 5.5
CVE-2025-27242

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

Fix: after 5.0.3
Fix from $1,600 2025-06-08