Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified CRITICAL 9.8
CVE-2024-44809

A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sani…

Mitigation only
Fix from $2,300 2024-09-03
Fusion HIGH 7.8
CVE-2024-38811

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with…

Fix: 13.6+
Fix from $1,950 2024-09-03
9205 Lte Modem Firmware HIGH 7.1
CVE-2024-23362

Cryptographic issue while parsing RSA keys in COBR format.

Mitigation only
Fix from $1,950 2024-09-02
Emc Xc Core Xcxr2 Firmware MEDIUM 6.0
CVE-2024-38303

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker w…

Fix: 2.22.1 / 2.22.2+
Fix from $1,600 2024-08-29
I Educar HIGH 8.1
CVE-2024-45058

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to…

Fix: after 2.9
Fix from $1,950 2024-08-28
Justenoughitems MEDIUM 5.3
CVE-2024-41565

JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specif…

Fix: 11.6.0.1021 / 13.1.0.18+
Fix from $1,600 2024-08-28
Netiq Advanced Authentication HIGH 8.2
CVE-2021-38122

A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information…

Fix: 6.3+
Fix from $1,950 2024-08-28
Thinmanager Thinserver CRITICAL 9.8
CVE-2024-7988

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code…

Fix: 11.1.8 / 11.2.9+
Fix from $2,300 2024-08-26
Web Application Firewall CRITICAL 9.8
CVE-2024-8073

Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issu…

Mitigation only
Fix from $2,300 2024-08-26
Unclassified CRITICAL 9.8
CVE-2024-45258

The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses…

Patch available
Fix from $2,300 2024-08-25
Fort Validator HIGH 7.5
CVE-2024-45236

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a…

Fix: 1.6.3+
Fix from $1,950 2024-08-24
Unclassified CRITICAL 9.8
CVE-2024-42531

Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a s…

Mitigation only
Fix from $2,300 2024-08-23
Idol2 CRITICAL 9.8
CVE-2024-45169

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper r…

Fix: after 2.12
Fix from $2,300 2024-08-22
Idol2 CRITICAL 9.8
CVE-2024-45167

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper r…

Fix: after 2.12
Fix from $2,300 2024-08-22
Chrome HIGH 8.8
CVE-2024-7974

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7977

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7980

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Aptio V HIGH 7.8
CVE-2024-33657

This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak informatio…

Fix: after 5.36
Fix from $1,950 2024-08-21
Netiq Self Service Password Reset MEDIUM 6.1
CVE-2020-11850

Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Pa…

Fix: 4.4+
Fix from $1,600 2024-08-21
Unclassified MEDIUM 6.5
CVE-2024-25009

Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can l…

Mitigation only
Fix from $1,600 2024-08-20
Unclassified HIGH 8.8
CVE-2024-7646EPSS 27%

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions`…

Patch available
Fix from $1,950 2024-08-16
Unclassified MEDIUM 6.8
CVE-2024-25008

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary co…

Mitigation only
Fix from $1,600 2024-08-16
Webcrack HIGH 7.8
CVE-2024-43373

webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifical…

Fix: 2.14.1+
Fix from $1,950 2024-08-15
Compactlogix 5380 Firmware HIGH 7.5
CVE-2024-7515

CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecov…

Fix: 34.014+
Fix from $1,950 2024-08-14
Compactlogix 5380 Firmware MEDIUM 6.5
CVE-2024-7507

CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is …

Fix: 34.014+
Fix from $1,600 2024-08-14
Illustrator HIGH 7.8
CVE-2024-41856

Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary…

Fix: 27.9.5 / 28.6+
Fix from $1,950 2024-08-14
Illustrator MEDIUM 5.5
CVE-2024-34118

Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-…

Fix: 27.9.5 / 28.6+
Fix from $1,600 2024-08-14
Server Board S2600st Firmware HIGH 8.2
CVE-2024-28947

Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileg…

Fix: 02.01.0017+
Fix from $1,950 2024-08-14
Nuc X15 Laptop Kit Lapbc510 Firmware HIGH 8.2
CVE-2024-34163

Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.

Fix: 0048 / 0065+
Fix from $1,950 2024-08-14
Unclassified HIGH 8.8
CVE-2024-21810

Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow a…

Mitigation only
Fix from $1,950 2024-08-14