Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Lguvr 8h Firmware HIGH 7.5
CVE-2024-22772

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Hvr 4781 Firmware HIGH 7.5
CVE-2024-22768

Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Hvr 8781 Firmware HIGH 7.5
CVE-2024-22769

Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Splunk HIGH 8.8
CVE-2024-23678

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the u…

Fix: 9.0.8 / 9.1.3+
Fix from $1,950 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-47141

IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial o…

Fix: 11.5.9+
Fix from $1,600 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-47158

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges t…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-47747

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to c…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-50308

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database …

Fix: 11.5.9+
Fix from $1,600 2024-01-22
Db2 HIGH 7.5
CVE-2023-45193

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted…

Fix: 11.5.9+
Fix from $1,950 2024-01-22
Db2 MEDIUM 6.5
CVE-2023-47746

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to c…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Nuc 8 Compute Element Cm8v5cb Firmware HIGH 7.8
CVE-2023-42766

Improper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege…

Mitigation only
Fix from $1,950 2024-01-19
Httpbeast CRITICAL 9.8
CVE-2023-50694

An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser…

Fix: after 0.4.1
Fix from $2,300 2024-01-19
Nuc 8 Home Nuc8i3behfa Firmware HIGH 7.8
CVE-2023-38587

Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

Mitigation only
Fix from $1,950 2024-01-19
Nuc 7 Essential Nuc7cjysamn Firmware HIGH 7.8
CVE-2023-28738

Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of priv…

Mitigation only
Fix from $1,950 2024-01-19
Nuc 9 Pro Compute Element Nuc9v7qnb Firmware HIGH 7.8
CVE-2023-28743

Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of priv…

Mitigation only
Fix from $1,950 2024-01-19
Nuc 8 Mainstream G Kit Nuc8i7inh Firmware HIGH 7.8
CVE-2023-29495

Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of priv…

Mitigation only
Fix from $1,950 2024-01-19
Android MEDIUM 5.5
CVE-2023-48354

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution pri…

Mitigation only
Fix from $1,600 2024-01-18
Android MEDIUM 5.5
CVE-2023-48346

In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges n…

No fix yet
Fix from $1,600 2024-01-18
Moveit Transfer HIGH 7.1
CVE-2024-0396

In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validat…

Fix: 2022.0.10 / 2022.1.11+
Fix from $1,950 2024-01-17
Workforce Access MEDIUM 5.5
CVE-2023-5097

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

Fix: 8.7+
Fix from $1,600 2024-01-16
Enterprise Server HIGH 8.8
CVE-2024-0507EPSS 66%

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability…

Fix: 3.8.13 / 3.9.8+
Fix from $1,950 2024-01-16
Fedora CRITICAL 9.8
CVE-2023-6395

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary co…

Patch available
Fix from $2,300 2024-01-16
Acrobat MEDIUM 5.5
CVE-2024-20721

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attac…

Fix: 120.0.2210.133+
Fix from $1,600 2024-01-15
Acrobat MEDIUM 5.5
CVE-2024-20709

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attac…

Fix: 120.0.2210.133+
Fix from $1,600 2024-01-15
Dgx A100 Firmware HIGH 7.8
CVE-2023-31035

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code …

Fix: 1.25+
Fix from $1,950 2024-01-12
Go Git HIGH 7.5
CVE-2023-49568

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of …

Fix: 5.11.0+
Fix from $1,950 2024-01-12
Quiz Maker MEDIUM 6.5
CVE-2024-22027

Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of…

Fix: 6.5.0.6+
Fix from $1,600 2024-01-12
Django MEDIUM 6.1
CVE-2024-22199

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability s…

Fix: 3.1.9+
Fix from $1,600 2024-01-11
Orbit Fox MEDIUM 5.4
CVE-2023-6781

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, an…

Fix: after 2.10.26
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45171

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-…

Mitigation only
Fix from $1,600 2024-01-11