Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Imanager CRITICAL 9.8
CVE-2024-3488

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a f…

Fix: 3.2.6+
Fix from $2,300 2024-05-15
Imanager CRITICAL 9.8
CVE-2024-3968

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upl…

Fix: 3.2.6+
Fix from $2,300 2024-05-15
Unclassified MEDIUM 6.4
CVE-2024-2248

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over …

Mitigation only
Fix from $1,600 2024-05-15
Acrobat Dc HIGH 7.8
CVE-2024-34098

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitr…

Fix: 20.005.30635 / 20.005.30636+
Fix from $1,950 2024-05-15
Automation Studio HIGH 7.2
CVE-2021-22280

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the co…

Fix: 4.12+
Fix from $1,950 2024-05-14
Unclassified HIGH 7.5
CVE-2024-3676

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthentic…

Mitigation only
Fix from $1,950 2024-05-14
Powerbi Javascript MEDIUM 6.5
CVE-2024-30054

Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability

Fix: 2.23.1+
Fix from $1,600 2024-05-14
Windows 10 1507 HIGH 8.8
CVE-2024-30040 KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

Fix: 10.0.10240.20651 / 10.0.14393.6981+
Fix from $1,950 2024-05-14
Windows 10 1809 MEDIUM 6.8
CVE-2024-30002

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.5820 / 10.0.19044.4412+
Fix from $1,600 2024-05-14
Windows 10 1809 MEDIUM 6.8
CVE-2024-29998

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.5820 / 10.0.19044.4412+
Fix from $1,600 2024-05-14
MongoDB HIGH 7.5
CVE-2024-3372

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and m…

Fix: 5.0.25 / 6.0.14+
Fix from $1,950 2024-05-14
Powerscale Onefs MEDIUM 6.5
CVE-2024-25970

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could pote…

Fix: 9.4.0.18 / 9.5.0.8+
Fix from $1,600 2024-05-14
Karaf Cave CRITICAL 9.1
CVE-2024-34365

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A…

Mitigation only
Fix from $2,300 2024-05-14
Emui HIGH 7.5
CVE-2024-32992

Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2024-05-14
Emui HIGH 7.5
CVE-2024-32989

Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availab…

No fix yet
Fix from $1,950 2024-05-14
Emui HIGH 7.5
CVE-2024-32990

Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availabil…

No fix yet
Fix from $1,950 2024-05-14
Unclassified MEDIUM 5.3
CVE-2024-32669

Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test cod…

Patch available
Fix from $1,600 2024-05-14
Unclassified MEDIUM 5.3
CVE-2024-32672

A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via …

Patch available
Fix from $1,600 2024-05-14
Fast Dds HIGH 7.5
CVE-2024-30258

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.…

Fix: 2.6.8 / 2.10.4+
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.1
CVE-2024-2257

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of passwor…

Mitigation only
Fix from $2,300 2024-05-14
Fedora HIGH 7.2
CVE-2024-25641EPSS 86%

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable …

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Unclassified HIGH 7.5
CVE-2024-25581

When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker…

Mitigation only
Fix from $1,950 2024-05-14
Dnf5 HIGH 8.4
CVE-2024-1929

Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity v…

Fix: 5.1.17+
Fix from $1,950 2024-05-08
Unclassified HIGH 8.8
CVE-2024-2746

Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unpr…

Mitigation only
Fix from $1,950 2024-05-08
Android MEDIUM 5.5
CVE-2024-0022

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profil…

Patch available
Fix from $1,600 2024-05-07
Android HIGH 7.8
CVE-2024-23705

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local…

Patch available
Fix from $1,950 2024-05-07
Android HIGH 7.8
CVE-2024-23706

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation…

Patch available
Fix from $1,950 2024-05-07
Android HIGH 7.8
CVE-2024-23707

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with…

Patch available
Fix from $1,950 2024-05-07
Mailinspector HIGH 7.5
CVE-2024-32371

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administra…

Fix: 5.2.19+
Fix from $1,950 2024-05-07
Unclassified MEDIUM 5.8
CVE-2023-7240

 An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perfo…

Mitigation only
Fix from $1,600 2024-05-07