Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Aqt1000 Firmware HIGH 7.8
CVE-2024-21476

Memory corruption when the channel ID passed by user is not validated and further used.

Mitigation only
Fix from $1,950 2024-05-06
Diaenergie CRITICAL 9.8
CVE-2024-4547

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is sp…

Fix: 1.10.01.004+
Fix from $2,300 2024-05-06
Diaenergie CRITICAL 9.8
CVE-2024-4548EPSS 29%

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is s…

Fix: 1.10.01.004+
Fix from $2,300 2024-05-06
Rdk B MEDIUM 6.7
CVE-2024-20056

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with Sys…

Mitigation only
Fix from $1,600 2024-05-06
Android HIGH 7.8
CVE-2024-20064

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2024-05-06
Unclassified MEDIUM 5.3
CVE-2024-34473

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration …

Mitigation only
Fix from $1,600 2024-05-04
Mex605 Firmware CRITICAL 9.8
CVE-2024-33792

netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.

No fix yet
Fix from $2,300 2024-05-03
Simple Editor HIGH 7.5
CVE-2023-40515

LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial…

Mitigation only
Fix from $1,950 2024-05-03
Uagateway MEDIUM 6.5
CVE-2023-32170

Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to c…

Fix: 1.5.13.487+
Fix from $1,600 2024-05-03
Essential Addons For Elementor MEDIUM 5.4
CVE-2024-4003

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cros…

Fix: 5.9.16+
Fix from $1,600 2024-05-02
Blocksy MEDIUM 5.4
CVE-2024-3747

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me block in all versions up to,…

Fix: 2.0.40+
Fix from $1,600 2024-05-02
Profilepress MEDIUM 5.4
CVE-2024-2867

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…

Fix: 4.15.5+
Fix from $1,600 2024-05-02
Exclusive Addons For Elementor MEDIUM 5.4
CVE-2024-2751

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ para…

Fix: 2.6.9.3+
Fix from $1,600 2024-05-02
Unclassified HIGH 8.0
CVE-2024-25290

An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.

Mitigation only
Fix from $1,950 2024-05-02
Unclassified MEDIUM 5.3
CVE-2024-0710

The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficien…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified CRITICAL 9.0
CVE-2024-4142

An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vuln…

Mitigation only
Fix from $2,300 2024-05-01
PHP MEDIUM 6.5
CVE-2024-3096

In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00…

Fix: 8.1.28 / 8.2.18+
Fix from $1,600 2024-04-29
Unclassified MEDIUM 6.5
CVE-2024-2756EPSS 38%

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard in…

Mitigation only
Fix from $1,600 2024-04-29
Vyper MEDIUM 5.3
CVE-2024-32645

Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_…

Fix: 0.4.0+
Fix from $1,600 2024-04-25
Vyper MEDIUM 5.3
CVE-2024-32646

Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `slice` builtin can result in a…

Fix: 0.4.0+
Fix from $1,600 2024-04-25
Glpi Agent HIGH 7.8
CVE-2024-28240

The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI packaging can allow a local u…

Fix: 1.7.2+
Fix from $1,950 2024-04-25
Unclassified MEDIUM 5.4
CVE-2024-4175

Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to send a malicious payload wit…

Mitigation only
Fix from $1,600 2024-04-25
Unclassified HIGH 7.5
CVE-2024-25583

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The …

Mitigation only
Fix from $1,950 2024-04-25
Repository Manager HIGH 7.8
CVE-2024-28976

Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could p…

Fix: 3.4.5+
Fix from $1,950 2024-04-24
Repository Manager MEDIUM 5.5
CVE-2024-28977

Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low privileges …

Fix: after 3.4.4
Fix from $1,600 2024-04-24
Unclassified MEDIUM 6.1
CVE-2024-32653

jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject ar…

Mitigation only
Fix from $1,600 2024-04-22
Unclassified HIGH 7.3
CVE-2023-38293

Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone…

Mitigation only
Fix from $1,950 2024-04-22
Embrace HIGH 7.5
CVE-2024-31841

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbi…

No fix yet
Fix from $1,950 2024-04-19
Enterprise Server HIGH 7.2
CVE-2024-3646

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.9.13 / 3.10.10+
Fix from $1,950 2024-04-19
Unclassified HIGH 8.1
CVE-2023-5397

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See …

No fix yet
Fix from $1,950 2024-04-17