Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Divi MEDIUM 5.4
CVE-2024-5533

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sani…

Fix: 4.25.2+
Fix from $1,600 2024-06-18
Unclassified HIGH 7.5
CVE-2024-37794

Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.

Mitigation only
Fix from $1,950 2024-06-17
Android HIGH 7.8
CVE-2024-32903

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local …

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-32907

In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege wi…

Mitigation only
Fix from $1,950 2024-06-13
Xps 8960 Firmware HIGH 8.2
CVE-2024-32859

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l…

Fix: 1.14.0 / 1.16.0+
Fix from $1,950 2024-06-13
Alienware Area 51m R2 Firmware HIGH 8.2
CVE-2024-32860

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l…

Fix: 1.0.24 / 1.1.12+
Fix from $1,950 2024-06-13
Xps 8960 Firmware HIGH 8.2
CVE-2024-32858

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l…

Fix: 1.14.0 / 1.16.0+
Fix from $1,950 2024-06-13
Xps 8960 Firmware MEDIUM 6.0
CVE-2024-32856

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l…

Fix: 1.14.0 / 1.16.0+
Fix from $1,600 2024-06-13
Commerce HIGH 7.2
CVE-2024-34108

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result …

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Commerce HIGH 7.2
CVE-2024-34109

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result …

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Windows 10 1507 HIGH 7.8
CVE-2024-30087EPSS 10%

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,950 2024-06-11
Windows 10 1507 HIGH 8.8
CVE-2024-30078EPSS 5%

Windows Wi-Fi Driver Remote Code Execution Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,950 2024-06-11
Sinec Traffic Analyzer MEDIUM 6.2
CVE-2024-35212

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input valida…

Fix: 1.2+
Fix from $1,600 2024-06-11
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Ipados MEDIUM 5.5
CVE-2024-27805

An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17…

Fix: 10.5 / 12.7.5+
Fix from $1,600 2024-06-10
Exynos 2200 Firmware HIGH 7.8
CVE-2024-31959

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, whi…

Mitigation only
Fix from $1,950 2024-06-07
Oneflow HIGH 7.5
CVE-2024-36734

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the …

Mitigation only
Fix from $1,950 2024-06-06
Oneflow HIGH 7.5
CVE-2024-36740

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.

Mitigation only
Fix from $1,950 2024-06-06
Oneflow HIGH 7.5
CVE-2024-36737

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the …

Mitigation only
Fix from $1,950 2024-06-06
Oneflow HIGH 7.5
CVE-2024-36745

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.index_sel…

Mitigation only
Fix from $1,950 2024-06-06
Oneflow HIGH 7.5
CVE-2024-36742

An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index parameter exc…

Mitigation only
Fix from $1,950 2024-06-06
Libaom CRITICAL 9.8
CVE-2024-5171

Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Ca…

Fix: after 3.9.0
Fix from $2,300 2024-06-05
Exynos 980 Firmware HIGH 7.1
CVE-2024-27378

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_acti…

Mitigation only
Fix from $1,950 2024-06-05
Finesse MEDIUM 6.1
CVE-2024-20405

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack…

Fix: 11.6+
Fix from $1,600 2024-06-05
Blocksy MEDIUM 5.4
CVE-2024-5439

The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.…

Fix: 2.0.51+
Fix from $1,600 2024-06-05
Fortiwebmanager HIGH 8.8
CVE-2024-23669

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-05
Rails CRITICAL 9.8
CVE-2024-28103

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o…

Fix: 6.1.7.8 / 7.0.8.4+
Fix from $2,300 2024-06-04
Apport HIGH 7.8
CVE-2022-1242

Apport can be tricked into connecting to arbitrary sockets as the root user

Fix: 2.21.0+
Fix from $1,950 2024-06-03
Fortiwebmanager HIGH 8.8
CVE-2024-23668

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-03
Devicehub HIGH 7.5
CVE-2024-36390

MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service

Mitigation only
Fix from $1,950 2024-06-02