Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ar8035 Firmware HIGH 7.8
CVE-2023-28574

Memory corruption in core services when Diag handler receives a command to configure event listeners.

No fix yet
Fix from $1,950 2023-11-07
Fastconnect 6700 Firmware HIGH 7.8
CVE-2023-21671

Memory Corruption in Core during syscall for Sectools Fuse comparison feature.

No fix yet
Fix from $1,950 2023-11-07
Platform HIGH 7.2
CVE-2023-5964

The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly valida…

Fix: 23.0+
Fix from $1,950 2023-11-06
Platform HIGH 7.2
CVE-2023-45161

The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL …

Fix: 20.1+
Fix from $1,950 2023-11-06
Platform HIGH 7.2
CVE-2023-45163

The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the inpu…

Fix: 18.1+
Fix from $1,950 2023-11-06
Csi Proxy HIGH 8.8
CVE-2023-3893

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escala…

Fix: after 1.1.2
Fix from $1,950 2023-11-03
Parsson HIGH 7.5
CVE-2023-4043

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-…

Fix: 1.0.5 / 1.1.4+
Fix from $1,950 2023-11-03
Glassfish CRITICAL 9.8
CVE-2023-5763

In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious c…

Fix: after 6.2.5
Fix from $2,300 2023-11-03
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41355

Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attac…

Mitigation only
Fix from $2,300 2023-11-03
Glpi CRITICAL 9.8
CVE-2023-42802

GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …

Fix: 10.0.10+
Fix from $2,300 2023-11-02
Meeting Server MEDIUM 5.3
CVE-2023-20255

A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of serv…

Fix: 3.6.1+
Fix from $1,600 2023-11-01
Secure Firewall Management Center HIGH 8.2
CVE-2023-20063

A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devic…

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
Secure Firewall Management Center MEDIUM 6.5
CVE-2023-20114

A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to dow…

Fix: after 7.3.1.1
Fix from $1,600 2023-11-01
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2023-20270

A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower …

Mitigation only
Fix from $1,600 2023-11-01
Solarwinds Platform HIGH 8.8
CVE-2023-40061

 Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.

Fix: 2023.4+
Fix from $1,950 2023-11-01
Solarwinds Platform HIGH 8.8
CVE-2023-40062

SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privi…

Fix: 2023.4+
Fix from $1,950 2023-11-01
Android MEDIUM 5.5
CVE-2022-48457

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional exec…

Mitigation only
Fix from $1,600 2023-11-01
Android MEDIUM 5.5
CVE-2022-48458

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional exec…

Mitigation only
Fix from $1,600 2023-11-01
Android MEDIUM 5.5
CVE-2022-48459

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional exec…

Mitigation only
Fix from $1,600 2023-11-01
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-4197EPSS 33%

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a…

Fix: after 18.0.1
Fix from $1,950 2023-11-01
Kubernetes HIGH 8.8
CVE-2023-3676EPSS 12%

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-10-31
Kubernetes HIGH 8.8
CVE-2023-3955

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-10-31
Android HIGH 7.5
CVE-2023-21391

In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of serv…

Fix: 14.0+
Fix from $1,950 2023-10-30
Thinkpad X13 Yoga Gen 2 Firmware MEDIUM 6.7
CVE-2022-4574

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges t…

Fix: 1.26 / 1.30+
Fix from $1,600 2023-10-30
Thinkpad X1 Fold Gen 1 Firmware MEDIUM 6.7
CVE-2022-4573

An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to exec…

Mitigation only
Fix from $1,600 2023-10-30
Thinkpad E14 Firmware MEDIUM 6.7
CVE-2022-48189

An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to…

Fix: 1.16 / 1.18+
Fix from $1,600 2023-10-30
Anythingllm CRITICAL 9.1
CVE-2023-5832

Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

Fix: 0.1.0+
Fix from $2,300 2023-10-30
Bluespice MEDIUM 5.4
CVE-2023-42431

Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile i…

Fix: 3.2.10.1 / 4.3.3+
Fix from $1,600 2023-10-30
Gm265dn Firmware MEDIUM 6.5
CVE-2022-3429

A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, t…

Fix: 02.06.00.04.00+
Fix from $1,600 2023-10-27
Factorytalk View HIGH 7.5
CVE-2023-46289

Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious …

Fix: after 13.0
Fix from $1,950 2023-10-27