Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Django Backend HIGH 8.8
CVE-2024-26164

Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability

Fix: 1.4.1+
Fix from $1,950 2024-03-12
Teams MEDIUM 5.0
CVE-2024-21448

Microsoft Teams for Android Information Disclosure Vulnerability

Fix: 1.0.0.2024022302+
Fix from $1,600 2024-03-12
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-25999

An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. 

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-26002

An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of spec…

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware CRITICAL 9.8
CVE-2024-25995

An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper i…

Fix: 1.5.1+
Fix from $2,300 2024-03-12
Charx Sec 3000 Firmware MEDIUM 5.3
CVE-2024-25997

An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

Fix: 1.5.1+
Fix from $1,600 2024-03-12
Android HIGH 8.8
CVE-2024-23717

In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This …

Patch available
Fix from $1,950 2024-03-11
Android MEDIUM 6.5
CVE-2024-0045

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjac…

Patch available
Fix from $1,600 2024-03-11
Anonymizer HIGH 8.8
CVE-2024-2339

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking functio…

Patch available
Fix from $1,950 2024-03-08
Editor MEDIUM 6.2
CVE-2024-27612EPSS 11%

Numbas editor before 7.3 mishandles editing of themes and extensions.

Fix: 7.3+
Fix from $1,600 2024-03-08
Editor HIGH 7.3
CVE-2024-27613

Numbas editor before 7.3 mishandles reading of themes and extensions.

Fix: 7.3+
Fix from $1,950 2024-03-08
macOS HIGH 7.8
CVE-2024-23294

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execu…

Fix: 14.4+
Fix from $1,950 2024-03-08
Ipados HIGH 8.6
CVE-2024-23246

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma…

Fix: 1.1 / 10.4+
Fix from $1,950 2024-03-08
Safari MEDIUM 6.5
CVE-2024-23263

A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, mac…

Fix: 1.1 / 10.4+
Fix from $1,600 2024-03-08
Artifactory HIGH 8.8
CVE-2023-42661

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution whe…

Fix: 7.76.2+
Fix from $1,950 2024-03-07
Booster For Woocommerce MEDIUM 5.4
CVE-2024-1534

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, an…

Fix: 7.1.8+
Fix from $1,600 2024-03-07
Deno MEDIUM 6.5
CVE-2024-27931

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would …

Fix: 1.41.1+
Fix from $1,600 2024-03-05
Ar8035 Firmware HIGH 7.5
CVE-2023-33103

Transient DOS while processing CAG info IE received from NW.

Mitigation only
Fix from $1,950 2024-03-04
315 5g Iot Modem Firmware HIGH 7.5
CVE-2023-33104

Transient DOS while processing PDU Release command with a parameter PDU ID out of range.

Mitigation only
Fix from $1,950 2024-03-04
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-28578

Memory corruption in Core Services while executing the command for removing a single event listener.

No fix yet
Fix from $1,950 2024-03-04
Android HIGH 7.2
CVE-2024-20034

In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,950 2024-03-04
Software Development Kit CRITICAL 9.8
CVE-2024-20017EPSS 46%

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additiona…

Fix: after 7.6.7.0
Fix from $2,300 2024-03-04
Mq HIGH 7.5
CVE-2024-25016

IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incor…

Fix: 9.0.0.23 / 9.1.0.20+
Fix from $1,950 2024-03-03
Hoppscotch MEDIUM 5.4
CVE-2024-27092

Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with …

Fix: 2023.12.6+
Fix from $1,600 2024-02-29
Indesign MEDIUM 5.5
CVE-2023-44345

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated…

Fix: 18.5.1+
Fix from $1,600 2024-02-29
Unclassified CRITICAL 9.1
CVE-2023-50737

The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an att…

Mitigation only
Fix from $2,300 2024-02-28
James HIGH 7.1
CVE-2023-51747

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a differ…

Mitigation only
Fix from $1,950 2024-02-27
Minder HIGH 7.5
CVE-2024-27093

Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a in…

Fix: after 0.0.31
Fix from $1,950 2024-02-26
Pretix CRITICAL 9.8
CVE-2024-27447

pretix before 2024.1.1 mishandles file validation.

Fix: 2024.1.1+
Fix from $2,300 2024-02-26
Ethernet Controller I225 It Firmware HIGH 8.6
CVE-2021-33141

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticate…

Fix: 1.87 / 29.0.1+
Fix from $1,950 2024-02-23