Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Aiomatic MEDIUM 5.3
CVE-2024-5969

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0…

Fix: 2.0.6+
Fix from $1,600 2024-07-27
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41120

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` va…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41115

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41116

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_par…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41117

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_par…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41119

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_par…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41114

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41112

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette …

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Streamlit Geospatial CRITICAL 9.8
CVE-2024-41113

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_par…

Fix: 2024-07-19+
Fix from $2,300 2024-07-26
Traffic Server HIGH 8.2
CVE-2024-35296

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic…

Fix: 8.1.11 / 9.2.5+
Fix from $1,950 2024-07-26
Roller MEDIUM 5.4
CVE-2024-25090

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …

Fix: 6.1.3+
Fix from $1,600 2024-07-26
Dotcms MEDIUM 6.1
CVE-2024-3938

The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be d…

Fix: 23.01.18 / 24.05.31+
Fix from $1,600 2024-07-25
Snapd MEDIUM 6.6
CVE-2024-29068

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image…

Fix: 2.62+
Fix from $1,600 2024-07-25
Telegram HIGH 8.1
CVE-2024-7014

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

Fix: 10.14.5+
Fix from $1,950 2024-07-23
Cxf HIGH 7.5
CVE-2024-32007

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…

Fix: 3.5.9 / 3.6.4+
Fix from $1,950 2024-07-19
Netty Incubator Codec Ohttp HIGH 8.1
CVE-2024-40642

The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class does not properly validate i…

Fix: 0.0.13+
Fix from $1,950 2024-07-18
Access Rights Manager HIGH 8.8
CVE-2024-23469EPSS 18%

SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenti…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Chrome HIGH 8.8
CVE-2024-3173

Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation vi…

Fix: 120.0.6099.62+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3172

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific…

Fix: 121.0.6167.85+
Fix from $1,950 2024-07-16
Chrome CRITICAL 9.6
CVE-2023-7012

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a mali…

Fix: 117.0.5938.62+
Fix from $2,300 2024-07-16
5015 Aenftxt Firmware HIGH 7.5
CVE-2024-6089

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapt…

Mitigation only
Fix from $1,950 2024-07-16
Workplace Desktop MEDIUM 5.5
CVE-2024-39827

Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduc…

Fix: 6.0.10+
Fix from $1,600 2024-07-15
Workplace Desktop HIGH 7.5
CVE-2024-27241

Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.17.13 / 6.0.0+
Fix from $1,950 2024-07-15
Rooms HIGH 7.8
CVE-2024-27240

Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local…

Fix: 5.17.13 / 6.0.0+
Fix from $1,950 2024-07-15
Seacms HIGH 8.8
CVE-2024-40518

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input d…

No fix yet
Fix from $1,950 2024-07-12
Seacms HIGH 8.8
CVE-2024-40520

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user in…

No fix yet
Fix from $1,950 2024-07-12
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2024-5681

CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel executi…

Fix: after 9.8
Fix from $1,950 2024-07-11
Junos MEDIUM 5.5
CVE-2024-39511

An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged at…

Fix: 20.4+
Fix from $1,600 2024-07-10
Junos Os Evolved MEDIUM 5.5
CVE-2024-39513

An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged …

Fix: 20.4+
Fix from $1,600 2024-07-10
Pan Os MEDIUM 6.8
CVE-2024-5913

An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical fil…

Fix: 10.1.14 / 10.2.10+
Fix from $1,600 2024-07-10