Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ninja Forms HIGH 7.2
CVE-2023-36505

Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6…

Fix: 3.6.25+
Fix from $1,950 2024-04-17
Chrome MEDIUM 6.1
CVE-2024-3841

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a p…

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Fedora MEDIUM 5.3
CVE-2022-24806

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can ex…

Patch available
Fix from $1,600 2024-04-16
Anythingllm HIGH 7.2
CVE-2024-3028

mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipu…

Fix: 1.0.0+
Fix from $1,950 2024-04-16
Anythingllm HIGH 8.0
CVE-2024-3029

In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-use…

Fix: 1.0.0+
Fix from $1,950 2024-04-16
Controllogix 5580 Firmware HIGH 7.5
CVE-2024-3493

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause …

Mitigation only
Fix from $1,950 2024-04-15
5015 Aenftxt Firmware HIGH 7.5
CVE-2024-2424

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverabl…

Mitigation only
Fix from $1,950 2024-04-15
Evolution HIGH 7.5
CVE-2024-29838

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticate…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Junos Os Evolved MEDIUM 6.5
CVE-2024-21590

An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper Networks Junos OS Evolved allows an unauthentica…

Fix: after 21.2
Fix from $1,600 2024-04-12
Open Sdn Controller MEDIUM 6.3
CVE-2024-29461

An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.

No fix yet
Fix from $1,600 2024-04-12
Pan Os CRITICAL 10.0
CVE-2024-3400 KEVEPSS 100%

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci…

Mitigation only
Fix from $2,300 2024-04-12
Fast Dds HIGH 7.1
CVE-2024-30916

An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive info…

Fix: after 2.14.0
Fix from $1,950 2024-04-11
Unclassified MEDIUM 5.3
CVE-2024-1481

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command argume…

Mitigation only
Fix from $1,600 2024-04-10
Pan Os HIGH 7.5
CVE-2024-3385

A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks ev…

Fix: 9.1.17 / 10.1.12+
Fix from $1,950 2024-04-10
Anythingllm HIGH 7.2
CVE-2024-3101

In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. …

Fix: 1.0.0+
Fix from $1,950 2024-04-10
Traffic Server HIGH 7.5
CVE-2024-31309EPSS 95%

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0…

Fix: 8.1.10 / 9.2.4+
Fix from $1,950 2024-04-10
Commerce CRITICAL 9.0
CVE-2024-20758

Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could r…

Mitigation only
Fix from $2,300 2024-04-10
Mysql2 MEDIUM 5.3
CVE-2024-21507

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poison…

Fix: 3.9.3+
Fix from $1,600 2024-04-10
Wp Chat App MEDIUM 5.4
CVE-2024-2513

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and inclu…

Fix: 3.6.3+
Fix from $1,600 2024-04-09
Seo MEDIUM 5.4
CVE-2024-2536

The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions …

Fix: 1.0.215+
Fix from $1,600 2024-04-09
Essential Addons For Elementor MEDIUM 6.4
CVE-2024-2650

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cros…

Fix: 5.9.11+
Fix from $1,600 2024-04-09
Otter Blocks MEDIUM 5.4
CVE-2024-2226

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…

Fix: 2.6.5+
Fix from $1,600 2024-04-09
Seopress MEDIUM 5.4
CVE-2024-2165

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and i…

Fix: 7.6+
Fix from $1,600 2024-04-09
Real Media Library MEDIUM 5.4
CVE-2024-2027

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attribute…

Fix: 4.22.8+
Fix from $1,600 2024-04-09
Unclassified MEDIUM 5.5
CVE-2024-25116

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users…

Patch available
Fix from $1,600 2024-04-09
Zeppelin MEDIUM 6.5
CVE-2024-31867

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Windows 10 1507 MEDIUM 6.8
CVE-2024-28897

Secure Boot Security Feature Bypass Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,600 2024-04-09
Windows 10 1507 MEDIUM 6.8
CVE-2024-26253

Windows rndismp6.sys Remote Code Execution Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,600 2024-04-09
Windows 10 1507 HIGH 8.0
CVE-2024-26240

Secure Boot Security Feature Bypass Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,950 2024-04-09
Windows 10 1507 HIGH 8.0
CVE-2024-26189

Secure Boot Security Feature Bypass Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,950 2024-04-09