Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Exynos 1380 Firmware MEDIUM 6.7
CVE-2024-27385

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no…

Mitigation only
Fix from $1,600 2024-07-09
Exynos 1380 Firmware MEDIUM 6.7
CVE-2024-27386

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no…

Mitigation only
Fix from $1,600 2024-07-09
Android HIGH 7.8
CVE-2024-31310

In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service s…

Patch available
Fix from $1,950 2024-07-09
Windows 10 1507 MEDIUM 6.5
CVE-2024-38105

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,600 2024-07-09
.net HIGH 7.5
CVE-2024-38095

.NET and Visual Studio Denial of Service Vulnerability

Fix: 8.0.7 / 17.4.21+
Fix from $1,950 2024-07-09
Windows 10 1507 MEDIUM 5.5
CVE-2024-38055

Microsoft Windows Codecs Library Information Disclosure Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,600 2024-07-09
Windows 10 1507 HIGH 7.8
CVE-2024-38052EPSS 7%

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,950 2024-07-09
Windows 10 1607 HIGH 7.8
CVE-2024-38043

PowerShell Elevation of Privilege Vulnerability

Fix: 10.0.14393.7159 / 10.0.17763.6054+
Fix from $1,950 2024-07-09
Windows 10 1607 HIGH 7.8
CVE-2024-38047

PowerShell Elevation of Privilege Vulnerability

Fix: 10.0.14393.7159 / 10.0.17763.6054+
Fix from $1,950 2024-07-09
Windows 10 1507 HIGH 7.3
CVE-2024-38033

PowerShell Elevation of Privilege Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,950 2024-07-09
365 Apps HIGH 8.8
CVE-2024-38021

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-07-09
Unclassified HIGH 8.2
CVE-2024-22271

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting …

Mitigation only
Fix from $1,950 2024-07-09
Discourse HIGH 7.5
CVE-2024-35227

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, …

Fix: after 3.2.2
Fix from $1,950 2024-07-03
Unclassified CRITICAL 9.1
CVE-2024-32755

Under certain circumstances the web interface will accept characters unrelated to the expected input.

No fix yet
Fix from $2,300 2024-07-02
Unclassified CRITICAL 10.0
CVE-2023-41917

Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending …

Mitigation only
Fix from $2,300 2024-07-02
Alienware M15 R6 Firmware MEDIUM 6.7
CVE-2024-0158

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit thi…

Fix: 1.2.0 / 1.2.1+
Fix from $1,600 2024-07-02
HTTP Server HIGH 7.5
CVE-2024-39573EPSS 35%

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to…

Fix: 2.4.60+
Fix from $1,950 2024-07-01
Compass CRITICAL 9.8
CVE-2024-6376

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass'…

Fix: 1.42.2+
Fix from $2,300 2024-07-01
Unclassified HIGH 7.5
CVE-2024-38525

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list o…

Mitigation only
Fix from $1,950 2024-06-28
Dryice Aex CRITICAL 9.8
CVE-2024-30110

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into…

Mitigation only
Fix from $2,300 2024-06-28
Filecatalyst Workflow CRITICAL 9.1
CVE-2024-5276EPSS 90%

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of admi…

Fix: 5.1.6+
Fix from $2,300 2024-06-25
Thinmanager CRITICAL 9.8
CVE-2024-5989

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause …

Fix: 11.1.8 / 11.2.9+
Fix from $2,300 2024-06-25
Thinmanager HIGH 7.5
CVE-2024-5990

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation Thin…

Fix: 11.1.8 / 11.2.9+
Fix from $1,950 2024-06-25
Thinmanager CRITICAL 9.8
CVE-2024-5988

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …

Fix: 11.1.8 / 11.2.9+
Fix from $2,300 2024-06-25
Opencart HIGH 7.2
CVE-2024-21519

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration fun…

No fix yet
Fix from $1,950 2024-06-22
Enterprise Linux HIGH 7.5
CVE-2024-6239

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed inp…

Fix: 24.06.0+
Fix from $1,950 2024-06-21
Unclassified MEDIUM 6.5
CVE-2024-38359

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logi…

No fix yet
Fix from $1,600 2024-06-20
Superset MEDIUM 5.3
CVE-2024-34693

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile ena…

Fix: 3.1.3 / 4.0.1+
Fix from $1,600 2024-06-20
Unclassified HIGH 7.3
CVE-2024-38355

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an unca…

Patch available
Fix from $1,950 2024-06-19
Unclassified MEDIUM 5.8
CVE-2024-4787

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This i…

Mitigation only
Fix from $1,600 2024-06-19