Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Emui MEDIUM 5.5
CVE-2023-49248

Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.

No fix yet
Fix from $1,600 2023-12-06
Serv U MEDIUM 5.0
CVE-2023-40053

A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Ser…

Mitigation only
Fix from $1,600 2023-12-06
Escargot CRITICAL 9.8
CVE-2023-41268

Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: fr…

Patch available
Fix from $2,300 2023-12-06
Telecontrol Configurator HIGH 7.5
CVE-2023-5188

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An…

Fix: 1.4.6.0+
Fix from $1,950 2023-12-05
315 5g Iot Modem Firmware HIGH 7.5
CVE-2023-33042

Transient DOS in Modem after RRC Setup message is received.

Mitigation only
Fix from $1,950 2023-12-05
Azure Rtos Threadx CRITICAL 9.8
CVE-2023-48693

Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arb…

Fix: 6.3.0+
Fix from $2,300 2023-12-05
Branch Names CRITICAL 9.8
CVE-2023-49291

tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions …

Fix: 7.0.0 / 7.0.7+
Fix from $2,300 2023-12-05
Android HIGH 7.8
CVE-2023-40097

In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local es…

Patch available
Fix from $1,950 2023-12-04
Traefik MEDIUM 6.5
CVE-2023-47106

Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, Traefik automatically URL enco…

Fix: after 2.10.5
Fix from $1,600 2023-12-04
Db2 HIGH 7.5
CVE-2023-40687

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RU…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-29258

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted fed…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-38727

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQ…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-46167

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted…

Fix: after 11.5.8
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-47701

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Fix: after 11.5.9
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-45178

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a specially crafted request is u…

Patch available
Fix from $1,950 2023-12-03
Infosphere Information Server HIGH 7.5
CVE-2023-40699

IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: …

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-12-01
Sel 451 Firmware MEDIUM 6.5
CVE-2023-34390

An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial o…

Mitigation only
Fix from $1,600 2023-11-30
Sel 411l Firmware MEDIUM 5.4
CVE-2023-2267

An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to perform reflection attacks agai…

No fix yet
Fix from $1,600 2023-11-30
Sel 411l Firmware HIGH 7.8
CVE-2023-2264

An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized…

No fix yet
Fix from $1,950 2023-11-30
Nexkey HIGH 7.5
CVE-2023-49095

nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another use…

Fix: 12.122.2+
Fix from $1,950 2023-11-30
Aiohttp MEDIUM 5.3
CVE-2023-49081

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HT…

Fix: 3.9.0+
Fix from $1,600 2023-11-30
Aiohttp MEDIUM 5.3
CVE-2023-49082

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the H…

Fix: 3.9.0+
Fix from $1,600 2023-11-29
Zld MEDIUM 5.5
CVE-2023-35136

An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmw…

Fix: after 5.37
Fix from $1,600 2023-11-28
Testing Platform HIGH 7.5
CVE-2023-48310

TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtered correctly. Nmap options are…

Fix: 2.1.1+
Fix from $1,950 2023-11-20
Fast Jwt MEDIUM 5.9
CVE-2023-48223

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm conf…

Fix: 3.3.2+
Fix from $1,600 2023-11-20
Css Tools MEDIUM 5.3
CVE-2023-26364

@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service …

Fix: 4.3.1+
Fix from $1,600 2023-11-17
Robohelp Server HIGH 7.5
CVE-2023-22272

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure …

Fix: after 11.4
Fix from $1,950 2023-11-17
Horizon MEDIUM 6.1
CVE-2023-40314

Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session informat…

Fix: 32.0.5 / 2023.1.9+
Fix from $1,600 2023-11-16
Precision 5820 Firmware MEDIUM 6.7
CVE-2023-32469

Dell Precision Tower BIOS contains an Improper Input Validation vulnerability. A locally authenticated malicious user with admin privileges could pot…

Fix: 2.32.0 / 2.36.0+
Fix from $1,600 2023-11-16
Redisgraph CRITICAL 9.8
CVE-2023-47003

An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsD…

No fix yet
Fix from $2,300 2023-11-16