Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Vios MEDIUM 5.5
CVE-2023-45169

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45175

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of…

Mitigation only
Fix from $1,600 2024-01-11
Vios MEDIUM 5.5
CVE-2023-45173

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of se…

Mitigation only
Fix from $1,600 2024-01-11
macOS HIGH 7.8
CVE-2023-42826

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.

Fix: 14.0+
Fix from $1,950 2024-01-10
Mf258 Firmware MEDIUM 6.1
CVE-2023-41781

There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack wil…

Mitigation only
Fix from $1,600 2024-01-10
.net MEDIUM 6.8
CVE-2024-21319

Microsoft Identity Denial of service vulnerability

Fix: 5.7.0 / 6.0.26+
Fix from $1,600 2024-01-09
.net Framework HIGH 7.5
CVE-2024-21312

.NET Framework Denial of Service Vulnerability

Patch available
Fix from $1,950 2024-01-09
Windows 10 1607 MEDIUM 6.1
CVE-2024-21316

Windows Server Key Distribution Service Security Feature Bypass

Fix: 10.0.14393.6614 / 10.0.17763.5329+
Fix from $1,600 2024-01-09
Windows 10 1507 MEDIUM 6.6
CVE-2024-20666

BitLocker Security Feature Bypass Vulnerability

Fix: 10.0.10240.20402 / 10.0.14393.6614+
Fix from $1,600 2024-01-09
Powershell CRITICAL 9.8
CVE-2024-0057

NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

Fix: 4.8.04690.01 / 4.8.04690.02+
Fix from $2,300 2024-01-09
Enterprise Security MEDIUM 6.5
CVE-2024-22165

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). …

Fix: 7.1.2+
Fix from $1,600 2024-01-09
Maxview Storage Manager CRITICAL 9.8
CVE-2023-51438

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All…

Fix: 4.14.00.26068+
Fix from $2,300 2024-01-09
Simatic Cn 4100 Firmware HIGH 7.5
CVE-2023-49252

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authent…

Fix: 2.7+
Fix from $1,950 2024-01-09
Discord Recon HIGH 8.8
CVE-2024-21663

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is…

Fix: 0.0.8+
Fix from $1,950 2024-01-09
Sidequest HIGH 8.8
CVE-2024-21625

SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (…

Fix: 0.10.35+
Fix from $1,950 2024-01-04
Zlib MEDIUM 5.5
CVE-2023-6992

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c…

Fix: 2023-11-16+
Fix from $1,600 2024-01-04
Pagelayer MEDIUM 5.4
CVE-2023-6738

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_head…

Fix: after 1.7.8
Fix from $1,600 2024-01-04
Froxlor HIGH 7.5
CVE-2023-50256

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fie…

Fix: 2.1.2+
Fix from $1,950 2024-01-03
Gpac HIGH 7.5
CVE-2023-46929

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows…

Patch available
Fix from $1,950 2024-01-03
Vapor MEDIUM 6.5
CVE-2024-21631

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a UR…

Fix: 4.90.0+
Fix from $1,600 2024-01-03
Mjs HIGH 7.5
CVE-2023-49551

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.

No fix yet
Fix from $1,950 2024-01-02
Prestashop MEDIUM 6.1
CVE-2024-21627

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` m…

Fix: 1.7.8.11 / 8.1.3+
Fix from $1,600 2024-01-02
Ar8035 Firmware MEDIUM 6.8
CVE-2023-33014

Information disclosure in Core services while processing a Diag command.

No fix yet
Fix from $1,600 2024-01-02
Follow Redirects MEDIUM 6.1
CVE-2023-26159

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.pa…

Fix: 1.15.4+
Fix from $1,600 2024-01-02
Lr13 HIGH 7.5
CVE-2023-32890

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execu…

Mitigation only
Fix from $1,950 2024-01-02
Dolphinscheduler HIGH 8.8
CVE-2023-49299

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed …

Fix: 3.1.9+
Fix from $1,950 2023-12-30
Verify Changed Files HIGH 8.8
CVE-2023-52137

The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames,…

Fix: 17.0.0+
Fix from $1,950 2023-12-29
Openoffice HIGH 8.8
CVE-2023-47804

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. …

Fix: 4.1.15+
Fix from $1,950 2023-12-29
D View 8 CRITICAL 9.8
CVE-2023-7163

A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. …

No fix yet
Fix from $2,300 2023-12-28
Fedora CRITICAL 9.8
CVE-2023-6879

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

Fix: 3.7.1+
Fix from $2,300 2023-12-27