Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Pwndoc MEDIUM 6.5
CVE-2024-55653

PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a…

Fix: 0.9.0+
Fix from $1,600 2024-12-10
Animate HIGH 7.8
CVE-2024-52982

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution …

Fix: 23.0.9 / 24.0.6+
Fix from $1,950 2024-12-10
Unclassified HIGH 7.3
CVE-2024-52051

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All ver…

Mitigation only
Fix from $1,950 2024-12-10
Openmanage Server Administrator HIGH 8.1
CVE-2024-45761

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malic…

Fix: 11.1.0.0+
Fix from $1,950 2024-12-09
Phone Contact Manager System HIGH 7.8
CVE-2024-12355

A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is th…

No fix yet
Fix from $1,950 2024-12-09
Phone Contact Manager System HIGH 7.8
CVE-2024-12353

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the funct…

No fix yet
Fix from $1,950 2024-12-09
Horilla HIGH 8.8
CVE-2024-12138

A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/creat…

Fix: after 1.2.1
Fix from $1,950 2024-12-04
Synapse MEDIUM 5.3
CVE-2024-52815

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnera…

Fix: 1.120.1+
Fix from $1,600 2024-12-03
Apq8017 Firmware HIGH 7.8
CVE-2024-43052

Memory corruption while processing API calls to NPU with invalid input.

Mitigation only
Fix from $1,950 2024-12-02
Unclassified MEDIUM 5.5
CVE-2024-52337

A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a control…

Mitigation only
Fix from $1,600 2024-11-26
Mdm9206 Firmware HIGH 7.8
CVE-2017-15832

Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

Mitigation only
Fix from $1,950 2024-11-26
Unclassified MEDIUM 6.3
CVE-2024-11662

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deplo…

Mitigation only
Fix from $1,600 2024-11-25
PHP HIGH 7.2
CVE-2024-11234

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option,…

Fix: 8.1.31 / 8.2.26+
Fix from $1,950 2024-11-24
Unified Secops Platform MEDIUM 6.5
CVE-2024-9257

Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion Vulnerability. This vulnerability allows remote attac…

Fix: 6.4.26+
Fix from $1,600 2024-11-22
Riot HIGH 7.5
CVE-2024-52802

RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net…

Fix: after 2024.04
Fix from $1,950 2024-11-22
Wsa8835 Firmware MEDIUM 6.7
CVE-2021-30299

Possible out of bound access in audio module due to lack of validation of user provided input.

Patch available
Fix from $1,600 2024-11-22
Unclassified MEDIUM 5.1
CVE-2024-52309

SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. One powerful feature …

Patch available
Fix from $1,600 2024-11-21
Unclassified HIGH 7.1
CVE-2024-9875

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundl…

Mitigation only
Fix from $1,950 2024-11-21
Workplace Desktop HIGH 7.5
CVE-2024-45422

Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.

Fix: 6.2.0+
Fix from $1,950 2024-11-19
Catalyst Sd Wan Manager MEDIUM 6.7
CVE-2021-1462

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected sy…

Mitigation only
Fix from $1,600 2024-11-18
Data Center Network Manager HIGH 8.1
CVE-2020-3538

A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacke…

Fix: 11.4+
Fix from $1,950 2024-11-18
Unclassified HIGH 7.7
CVE-2024-0793

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp blo…

Patch available
Fix from $1,950 2024-11-17
Unclassified MEDIUM 6.7
CVE-2021-34752

A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrar…

Mitigation only
Fix from $1,600 2024-11-15
Catalyst Sd Wan Manager MEDIUM 6.4
CVE-2021-1482

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass a…

Mitigation only
Fix from $1,600 2024-11-15
Catalyst Sd Wan Manager MEDIUM 5.0
CVE-2021-1464

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restric…

Mitigation only
Fix from $1,600 2024-11-15
Catalyst Sd Wan Manager MEDIUM 5.4
CVE-2021-1466

A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow …

Mitigation only
Fix from $1,600 2024-11-15
Unclassified HIGH 7.5
CVE-2022-2232

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perf…

Mitigation only
Fix from $1,950 2024-11-14
Traffic Server HIGH 7.5
CVE-2024-50305

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2…

Fix: 9.2.6+
Fix from $1,950 2024-11-14
Traffic Server HIGH 7.5
CVE-2024-38479

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 th…

Fix: 9.2.6+
Fix from $1,950 2024-11-14
M10jnp2sb Firmware MEDIUM 6.7
CVE-2024-41167

Improper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable escalatio…

Fix: after 7.220
Fix from $1,600 2024-11-13