Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Enterprise Server HIGH 8.0
CVE-2024-1354

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $1,950 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1355

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
Enterprise Server CRITICAL 9.1
CVE-2024-1359

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t…

Fix: 3.8.15 / 3.9.10+
Fix from $2,300 2024-02-13
365 Apps CRITICAL 9.8
CVE-2024-21413 KEVEPSS 95%

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2024-02-13
Teams MEDIUM 5.0
CVE-2024-21374

Microsoft Teams for Android Information Disclosure Vulnerability

Fix: 1.0.0.2024022302+
Fix from $1,600 2024-02-13
Defender For Endpoint HIGH 7.8
CVE-2024-21315

Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability

Fix: 6.2.9200.24569 / 6.2.9200.24710+
Fix from $1,950 2024-02-13
Windows 11 21h2 MEDIUM 6.5
CVE-2024-20684

Windows Hyper-V Denial of Service Vulnerability

Fix: 10.0.20348.2322 / 10.0.22000.2777+
Fix from $1,600 2024-02-13
Envoy HIGH 7.5
CVE-2024-23324

Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can forc…

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Zabbix MEDIUM 5.4
CVE-2024-22119

The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

Fix: 5.0.40 / 6.0.24+
Fix from $1,600 2024-02-09
Intellij Idea MEDIUM 5.3
CVE-2024-24941

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

Fix: 2023.3.3+
Fix from $1,600 2024-02-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2023-33057

Transient DOS in Multi-Mode Call Processor while processing UE policy container.

No fix yet
Fix from $1,950 2024-02-06
Root Quick Reboot HIGH 7.5
CVE-2023-47355

The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff,…

No fix yet
Fix from $1,950 2024-02-05
Nr15 HIGH 7.5
CVE-2024-20003

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid N…

Mitigation only
Fix from $1,950 2024-02-05
Nr15 HIGH 7.5
CVE-2024-20004

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid N…

Mitigation only
Fix from $1,950 2024-02-05
Openharmony MEDIUM 6.2
CVE-2024-21863

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Fix: after 3.2.4
Fix from $1,600 2024-02-02
Openharmony MEDIUM 5.5
CVE-2024-0285

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Fix: after 3.2.4
Fix from $1,600 2024-02-02
Storage Ceph MEDIUM 6.5
CVE-2023-46159

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 26…

Patch available
Fix from $1,600 2024-02-02
Feverwarn Firmware HIGH 8.1
CVE-2023-49610

MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message run…

Mitigation only
Fix from $1,950 2024-02-01
Edge Chromium MEDIUM 6.5
CVE-2024-21388EPSS 32%

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 121.0.2277.83+
Fix from $1,600 2024-01-30
Modsecurity HIGH 8.6
CVE-2024-1019

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSec…

Fix: 3.0.12+
Fix from $1,950 2024-01-30
Appbuilder HIGH 7.1
CVE-2023-4552

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with th…

Fix: 23.2+
Fix from $1,950 2024-01-29
Appbuilder MEDIUM 5.3
CVE-2023-4553

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are view…

Fix: 23.2+
Fix from $1,600 2024-01-29
Appbuilder HIGH 7.5
CVE-2023-4550

Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe Sy…

Fix: 23.2+
Fix from $1,950 2024-01-29
Appbuilder HIGH 8.8
CVE-2023-4551

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionali…

Fix: 23.2+
Fix from $1,950 2024-01-29
Otrs CRITICAL 9.8
CVE-2024-23790

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. T…

Fix: 7.0.49 / 2024.1.1+
Fix from $2,300 2024-01-29
Tutanota MEDIUM 5.3
CVE-2024-23655

Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so th…

Fix: 3.119.10+
Fix from $1,600 2024-01-25
Adapter Node HIGH 7.5
CVE-2024-23641

SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `R…

Fix: 2.1.2 / 2.4.3+
Fix from $1,950 2024-01-24
Lguvr 16h Firmware HIGH 7.5
CVE-2024-23842

Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Hvr 16781 Firmware HIGH 7.5
CVE-2024-22770

Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Lguvr 4h Firmware HIGH 7.5
CVE-2024-22771

Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23