Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 5.4
CVE-2025-32073

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediaw…

Mitigation only
Fix from $1,600 2025-04-11
Ipad Os HIGH 7.8
CVE-2023-42977

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to bre…

Fix: 14.0 / 17.0+
Fix from $1,950 2025-04-11
macOS MEDIUM 5.4
CVE-2023-42981

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed w…

Mitigation only
Fix from $1,600 2025-04-11
Maximo Application Suite MEDIUM 6.5
CVE-2023-43037

IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.

Fix: 8.11.13+
Fix from $1,600 2025-04-10
Junos HIGH 7.4
CVE-2025-30648

An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenti…

Fix: 21.2+
Fix from $1,950 2025-04-09
Junos HIGH 7.5
CVE-2025-30649

An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-…

Fix: 22.2+
Fix from $1,950 2025-04-09
Poi MEDIUM 5.3
CVE-2025-31672

Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma…

Fix: 5.4.0+
Fix from $1,600 2025-04-09
Unclassified HIGH 7.8
CVE-2025-2223

CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstat…

Mitigation only
Fix from $1,950 2025-04-09
Coldfusion MEDIUM 6.8
CVE-2025-30293

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security f…

Mitigation only
Fix from $1,600 2025-04-08
Coldfusion MEDIUM 6.8
CVE-2025-30294EPSS 16%

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security f…

Mitigation only
Fix from $1,600 2025-04-08
Coldfusion CRITICAL 9.1
CVE-2025-24446

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary co…

Mitigation only
Fix from $2,300 2025-04-08
Dynamics 365 Business Central 2023 MEDIUM 5.5
CVE-2025-29821

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

Fix: 23.18.32409 / 24.12.32447+
Fix from $1,600 2025-04-08
Windows 11 22h2 HIGH 7.8
CVE-2025-29811

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5189 / 10.0.22631.5189+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.6
CVE-2025-27737

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-27731

Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Azure Stack Hci 22h2 HIGH 7.8
CVE-2025-27489

Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.3328 / 10.0.25398.1486+
Fix from $1,950 2025-04-08
Windows Server 2008 HIGH 8.8
CVE-2025-26647

Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-24058

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-24060

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 21h2 HIGH 7.8
CVE-2025-24062

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.5737 / 10.0.19045.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-24073

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-24074

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Shopware HIGH 7.5
CVE-2025-30151

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-AP…

Fix: 6.5.8.17 / 6.6.10.3+
Fix from $1,950 2025-04-08
Springboot Admin HIGH 8.8
CVE-2025-3413

A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this…

Fix: after 2017-12-26
Fix from $1,950 2025-04-08
Eladmin MEDIUM 6.5
CVE-2025-3250

A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of t…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified MEDIUM 5.3
CVE-2025-3165

A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend…

Mitigation only
Fix from $1,600 2025-04-03
Lmdeploy HIGH 7.8
CVE-2025-3162

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file…

Fix: after 0.7.1
Fix from $1,950 2025-04-03
Plugin Shell CRITICAL 9.8
CVE-2025-31477

The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open progr…

Fix: 2.2.1+
Fix from $2,300 2025-04-02
Pexip Infinity HIGH 7.5
CVE-2025-30080

Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of …

Fix: 37.0+
Fix from $1,950 2025-04-02
Pexip Infinity HIGH 7.5
CVE-2024-37917

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted s…

Fix: 35.0+
Fix from $1,950 2025-04-02