Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ios Xr HIGH 8.6
CVE-2025-20146

A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact Hi…

Mitigation only
Fix from $1,950 2025-03-12
Ios Xr HIGH 8.6
CVE-2025-20142

A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000…

Mitigation only
Fix from $1,950 2025-03-12
Sipass Integrated Ac5102 \(acc G2\) Firmware MEDIUM 6.7
CVE-2025-27493

A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). A…

Fix: 6.4.9+
Fix from $1,600 2025-03-11
Sipass Integrated Ac5102 \(acc G2\) Firmware HIGH 7.2
CVE-2025-27494

A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). A…

Fix: 6.4.9+
Fix from $1,950 2025-03-11
Goldendb HIGH 7.5
CVE-2025-26702

Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.04.

Fix: 6.1.03.05+
Fix from $1,950 2025-03-11
Pb Cms HIGH 7.2
CVE-2025-2043

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#theme…

Mitigation only
Fix from $1,950 2025-03-06
Traffic Server MEDIUM 6.3
CVE-2024-38311

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…

Fix: 9.2.9 / 10.0.4+
Fix from $1,600 2025-03-06
Unclassified CRITICAL 9.3
CVE-2025-27517

Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lead to remote code execution wi…

Mitigation only
Fix from $2,300 2025-03-05
Debian Linux HIGH 7.8
CVE-2025-1080

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice…

Fix: 24.8.5.1 / 25.2.1.1+
Fix from $1,950 2025-03-04
Ultimate Auction MEDIUM 6.3
CVE-2025-0958

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including…

Fix: 4.3.0+
Fix from $1,600 2025-03-04
Emui MEDIUM 5.5
CVE-2024-58044

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-03-04
Qam8255p Firmware HIGH 8.8
CVE-2024-53029

Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

Mitigation only
Fix from $1,950 2025-03-03
Msm8996au Firmware HIGH 7.8
CVE-2024-53030

Memory corruption while processing input message passed from FE driver.

No fix yet
Fix from $1,950 2025-03-03
Srv1l Firmware HIGH 7.8
CVE-2024-53031

Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

No fix yet
Fix from $1,950 2025-03-03
Qam8255p Firmware HIGH 7.8
CVE-2024-53012

Memory corruption may occur due to improper input validation in clock device.

No fix yet
Fix from $1,950 2025-03-03
Qam8255p Firmware HIGH 7.8
CVE-2024-53022

Memory corruption may occur during communication between primary and guest VM.

No fix yet
Fix from $1,950 2025-03-03
Wpforo Forum MEDIUM 6.5
CVE-2025-0764

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Member…

Fix: 2.4.2+
Fix from $1,600 2025-02-28
Nios CRITICAL 9.8
CVE-2024-36047

Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.

Fix: 8.6.4+
Fix from $2,300 2025-02-27
Libreoffice HIGH 7.8
CVE-2025-0514

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditio…

Fix: 24.8.5.1+
Fix from $1,950 2025-02-25
Cicadascms CRITICAL 9.8
CVE-2025-1556

A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the fil…

No fix yet
Fix from $2,300 2025-02-22
Comboblocks MEDIUM 5.3
CVE-2024-13798

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and includi…

Fix: 2.3.6+
Fix from $1,600 2025-02-22
Uncode HIGH 7.5
CVE-2024-13681

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in…

Fix: 2.9.1.7+
Fix from $1,950 2025-02-18
Uncode MEDIUM 6.5
CVE-2024-13691

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all …

Fix: 2.9.1.7+
Fix from $1,600 2025-02-18
Unclassified HIGH 8.6
CVE-2025-0422

An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execu…

Mitigation only
Fix from $1,950 2025-02-18
Unclassified MEDIUM 5.3
CVE-2025-0423

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting…

Mitigation only
Fix from $1,600 2025-02-18
Unclassified MEDIUM 5.1
CVE-2025-0424

In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting v…

Mitigation only
Fix from $1,600 2025-02-18
Fireware MEDIUM 6.1
CVE-2025-0178

An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host …

Fix: 12.5.13 / 12.11.1+
Fix from $1,600 2025-02-14
Unclassified MEDIUM 6.5
CVE-2025-0815

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to th…

No fix yet
Fix from $1,600 2025-02-13
Unclassified MEDIUM 6.5
CVE-2025-0816

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the …

Mitigation only
Fix from $1,600 2025-02-13
Unclassified MEDIUM 5.3
CVE-2025-0814

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicio…

Mitigation only
Fix from $1,600 2025-02-13