Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Nessus Network Monitor HIGH 7.2
CVE-2023-5624

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter paramete…

Fix: 6.3.0+
Fix from $1,950 2023-10-26
Ingress Nginx HIGH 8.8
CVE-2023-5043

Ingress nginx annotation injection causes arbitrary command execution.

Fix: 1.9.0+
Fix from $1,950 2023-10-25
Ingress Nginx HIGH 8.8
CVE-2023-5044EPSS 57%

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

Fix: 1.9.0+
Fix from $1,950 2023-10-25
Ingress Nginx MEDIUM 6.5
CVE-2022-4886

Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

Fix: 1.8.0+
Fix from $1,600 2023-10-25
Client Connector HIGH 7.8
CVE-2021-26736

Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low …

Fix: 3.6+
Fix from $1,950 2023-10-23
Pdm HIGH 7.8
CVE-2023-45805

pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could all…

Fix: 0.11.2 / 2.10.0+
Fix from $1,950 2023-10-20
Traffic Server HIGH 7.5
CVE-2023-39456EPSS 53%

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th…

Fix: 9.2.3+
Fix from $1,950 2023-10-17
Security Verify Privilege On Premises HIGH 7.1
CVE-2021-29913

IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due t…

Fix: 11.5+
Fix from $1,950 2023-10-17
Db2 HIGH 7.5
CVE-2023-40372

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement usin…

Fix: after 11.5.8
Fix from $1,950 2023-10-17
Db2 HIGH 7.5
CVE-2023-40373

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common…

Fix: after 11.5.8
Fix from $1,950 2023-10-17
Db2 HIGH 7.5
CVE-2023-30991

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. I…

Fix: after 11.5.8
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-40374

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted query statement. …

Fix: after 11.5.8
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-38740

IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted SQL statement. …

Fix: after 11.5.8
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-38728

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted XM…

Fix: 11.5.8+
Fix from $1,950 2023-10-16
Fiber HIGH 8.8
CVE-2023-45128

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w…

Fix: 2.50.0+
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-30987

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Fix: 11.5.8+
Fix from $1,950 2023-10-16
Db2 HIGH 7.5
CVE-2023-38720

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with a specially crafted ALTER TAB…

Fix: 11.5.8+
Fix from $1,950 2023-10-16
Otrs MEDIUM 5.5
CVE-2023-5421

An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute…

Fix: 7.0.47 / 8.0.37+
Fix from $1,600 2023-10-16
App Connect Enterprise MEDIUM 5.5
CVE-2023-45176

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a d…

Fix: after 12.0.10.0
Fix from $1,600 2023-10-14
Factorytalk Linx CRITICAL 9.1
CVE-2023-29464EPSS 10%

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa…

Mitigation only
Fix from $2,300 2023-10-13
Vrite HIGH 7.5
CVE-2023-5571

Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.

Fix: 0.3.0+
Fix from $1,950 2023-10-13
Junos MEDIUM 6.5
CVE-2023-44204

An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolve…

Mitigation only
Fix from $1,600 2023-10-13
Junos HIGH 7.5
CVE-2023-44185

An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (…

Fix: 20.4+
Fix from $1,950 2023-10-13
Junos HIGH 7.5
CVE-2023-44192

An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based atta…

Fix: 20.4+
Fix from $1,950 2023-10-13
Junos MEDIUM 5.3
CVE-2023-44183

An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series …

Mitigation only
Fix from $1,600 2023-10-13
Zabbix MEDIUM 5.4
CVE-2023-32721

A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

Fix: after 6.4.5
Fix from $1,600 2023-10-12
Harmonyos HIGH 7.5
CVE-2023-44103

Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-10-11
Tomcat MEDIUM 5.3
CVE-2023-45648EPSS 6%

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro…

Fix: 8.5.94 / 9.0.81+
Fix from $1,600 2023-10-10
Windows 10 1507 HIGH 7.8
CVE-2023-36731EPSS 8%

Win32k Elevation of Privilege Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows 10 HIGH 8.0
CVE-2023-36697

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10