Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Pexip Infinity HIGH 7.5
CVE-2023-31289

Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

Fix: 31.2+
Fix from $1,950 2023-12-25
Pexip Infinity HIGH 7.5
CVE-2023-31455

Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

Fix: 31.2+
Fix from $1,950 2023-12-25
Inspiron 7510 Firmware MEDIUM 6.7
CVE-2023-39251

Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerabili…

Fix: 1.20.0 / 1.23.0+
Fix from $1,600 2023-12-22
Aix MEDIUM 5.5
CVE-2023-45165

IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-For…

Mitigation only
Fix from $1,600 2023-12-22
Toby L200 Firmware MEDIUM 6.8
CVE-2023-0011

A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This v…

Mitigation only
Fix from $1,600 2023-12-20
Urbancode Deploy MEDIUM 5.5
CVE-2023-42012

An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject…

Fix: after 7.3.2.2
Fix from $1,600 2023-12-20
Urbancode Deploy MEDIUM 6.5
CVE-2023-47161

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive f…

Fix: after 7.3.2.2
Fix from $1,600 2023-12-20
Vios MEDIUM 5.5
CVE-2023-45172

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X…

Patch available
Fix from $1,600 2023-12-19
Cpp13 Firmware HIGH 7.2
CVE-2023-39509

A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o…

Fix: after 8.90
Fix from $1,950 2023-12-18
Zabbix Agent2 CRITICAL 9.8
CVE-2023-32728

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f…

Fix: after 6.4.8
Fix from $2,300 2023-12-18
Zabbix Server HIGH 7.2
CVE-2023-32727

An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitr…

Fix: after 6.4.7
Fix from $1,950 2023-12-18
Tutanota HIGH 8.8
CVE-2023-46116

Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.1…

Fix: 3.118.12+
Fix from $1,950 2023-12-15
Sigma Lite Firmware HIGH 7.5
CVE-2023-33217

By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the ter…

Fix: 1.2.7 / 2.12.2+
Fix from $1,950 2023-12-15
Api Manager MEDIUM 5.3
CVE-2023-6835

Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manip…

Mitigation only
Fix from $1,600 2023-12-15
Css Tools HIGH 7.5
CVE-2023-48631

@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while…

Fix: 4.3.2+
Fix from $1,950 2023-12-14
Mf833u1 Firmware HIGH 8.0
CVE-2023-25651

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an auth…

Mitigation only
Fix from $1,950 2023-12-14
Zxcloud Irai MEDIUM 6.5
CVE-2023-25650

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker w…

Fix: 7.23.30+
Fix from $1,600 2023-12-14
Cube.js HIGH 7.5
CVE-2023-50709

Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitti…

Fix: 0.34.34+
Fix from $1,950 2023-12-13
Dompdf HIGH 7.5
CVE-2023-50262

Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that paths within the SVG are all…

Fix: after 2.0.3
Fix from $1,950 2023-12-13
After Effects HIGH 7.8
CVE-2023-48634

Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could resu…

Fix: after 24.0.3
Fix from $1,950 2023-12-13
Supermailer MEDIUM 5.5
CVE-2023-6381

Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerabili…

Mitigation only
Fix from $1,600 2023-12-13
Office Long Term Servicing Channel MEDIUM 5.3
CVE-2023-35619

Microsoft Outlook for Mac Spoofing Vulnerability

Patch available
Fix from $1,600 2023-12-12
Opcenter Quality HIGH 7.5
CVE-2023-46285

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo…

Fix: 4.1 / 15+
Fix from $1,950 2023-12-12
Mindsdb MEDIUM 5.3
CVE-2023-49796

MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file write vulnerability in `file.py…

Patch available
Fix from $1,600 2023-12-11
Chromecast Firmware CRITICAL 9.8
CVE-2023-48425

U-Boot vulnerability resulting in persistent Code Execution 

Fix: 2023-10-01+
Fix from $2,300 2023-12-11
Candid HIGH 7.5
CVE-2023-6245

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `rec…

Fix: 0.9.10+
Fix from $1,950 2023-12-08
Securecore Technology HIGH 7.8
CVE-2023-5058

Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows…

Mitigation only
Fix from $1,950 2023-12-07
Open Charge Point Protocol HIGH 7.5
CVE-2023-49958

An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandl…

Fix: after 1.2.0
Fix from $1,950 2023-12-07
Aptio V HIGH 7.8
CVE-2023-39538

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A s…

Mitigation only
Fix from $1,950 2023-12-06
Aptio V HIGH 7.8
CVE-2023-39539

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A s…

Mitigation only
Fix from $1,950 2023-12-06