Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows Server 2008 MEDIUM 6.5
CVE-2023-36706

Windows Deployment Services Information Disclosure Vulnerability

Patch available
Fix from $1,600 2023-10-10
Windows Server 2012 HIGH 7.5
CVE-2023-36707

Windows Deployment Services Denial of Service Vulnerability

Patch available
Fix from $1,950 2023-10-10
Windows 10 1507 HIGH 7.5
CVE-2023-36585

Windows upnphost.dll Denial of Service Vulnerability

Fix: 10.0.10240.20232 / 10.0.17763.4974+
Fix from $1,950 2023-10-10
Windows 10 1507 MEDIUM 5.5
CVE-2023-36563 KEVEPSS 21%

Microsoft WordPad Information Disclosure Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,600 2023-10-10
Common Data Model Sdk MEDIUM 6.5
CVE-2023-36566

Microsoft Common Data Model SDK Denial of Service Vulnerability

Fix: 1.7.4+
Fix from $1,600 2023-10-10
Windows 10 1507 CRITICAL 9.8
CVE-2023-35349

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $2,300 2023-10-10
Smartfabric Storage Software CRITICAL 9.8
CVE-2023-32485

Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exp…

Fix: 1.4.0+
Fix from $2,300 2023-10-05
Smartfabric Storage Software MEDIUM 6.5
CVE-2023-43073

Dell SmartFabric Storage Software v1.4 (and earlier) contains an Improper Input Validation vulnerability in RADIUS configuration. An authenticated re…

Fix: 1.4.1+
Fix from $1,600 2023-10-05
Altair HIGH 7.8
CVE-2023-43799

Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them…

Fix: 5.2.5+
Fix from $1,950 2023-10-04
Session Border Controller CRITICAL 9.8
CVE-2023-36619

Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

No fix yet
Fix from $2,300 2023-10-04
Hydra HIGH 8.1
CVE-2023-42449

Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head initializer to extract one or m…

Fix: 0.13.0+
Fix from $1,950 2023-10-04
Hydra CRITICAL 9.1
CVE-2023-38701

Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head firs…

Fix: 0.12.0+
Fix from $2,300 2023-10-04
Linux Kernel HIGH 8.2
CVE-2023-39191

An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic…

Fix: 6.3+
Fix from $1,950 2023-10-04
Hydra HIGH 8.1
CVE-2023-42448

Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum …

Fix: 0.13.0+
Fix from $1,950 2023-10-04
Confluence Data Center CRITICAL 9.8
CVE-2023-22515 KEVEPSS 99%

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnera…

Fix: 8.3.3 / 8.4.3+
Fix from $2,300 2023-10-04
Data Grid HIGH 7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…

Mitigation only
Fix from $1,950 2023-10-04
Android HIGH 7.8
CVE-2023-30690

Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

Mitigation only
Fix from $1,950 2023-10-04
Artifactory MEDIUM 6.5
CVE-2023-42508

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticate…

Fix: 7.66.0+
Fix from $1,600 2023-10-03
Ar8035 Firmware HIGH 7.8
CVE-2023-24853

Memory Corruption in HLOS while registering for key provisioning notify.

No fix yet
Fix from $1,950 2023-10-03
Apq8064au Firmware HIGH 8.2
CVE-2023-22382

Weak configuration in Automotive while VM is processing a listener request from TEE.

No fix yet
Fix from $1,950 2023-10-03
Ingepac Fc5066 Firmware HIGH 7.5
CVE-2023-3769

Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would al…

Mitigation only
Fix from $1,950 2023-10-02
Ingepac Da3451 Firmware HIGH 7.5
CVE-2023-3768

Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would al…

Mitigation only
Fix from $1,950 2023-10-02
Android MEDIUM 6.7
CVE-2023-32826

In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,600 2023-10-02
Android MEDIUM 6.7
CVE-2023-32827

In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,600 2023-10-02
Linux Kernel HIGH 7.5
CVE-2023-32820

In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no addition…

Mitigation only
Fix from $1,950 2023-10-02
Ios Xe HIGH 8.8
CVE-2023-20231

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affect…

Mitigation only
Fix from $1,950 2023-09-27
Opencart HIGH 8.8
CVE-2023-2315

Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out ar…

Fix: after 4.0.2.2
Fix from $1,950 2023-09-27
Emui HIGH 7.5
CVE-2023-41300

Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to rest…

No fix yet
Fix from $1,950 2023-09-25
Emui HIGH 7.5
CVE-2023-41303

Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock …

Mitigation only
Fix from $1,950 2023-09-25
Emui CRITICAL 9.8
CVE-2022-48605

Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and…

No fix yet
Fix from $2,300 2023-09-25