Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Dar 7000 Firmware CRITICAL 9.8
CVE-2023-5143

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 up to 20151231. This issue affec…

Fix: after 20151231
Fix from $2,300 2023-09-24
Automataci CRITICAL 9.1
CVE-2023-42798

AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a rele…

Fix: 1.5.0+
Fix from $2,300 2023-09-22
Quinn HIGH 7.5
CVE-2023-42805

quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet co…

Fix: 0.9.5 / 0.10.5+
Fix from $1,950 2023-09-21
Openharmony MEDIUM 5.5
CVE-2023-4753

OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.

Fix: after 3.2.1
Fix from $1,600 2023-09-21
Nocodb MEDIUM 6.5
CVE-2023-5104

Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.

Fix: 0.96.0+
Fix from $1,600 2023-09-21
Dgx H100 Firmware HIGH 8.8
CVE-2023-31013

NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this…

Fix: 23.08.18+
Fix from $1,950 2023-09-20
Dgx H100 Firmware HIGH 8.8
CVE-2023-31011

NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this …

Fix: 23.08.18+
Fix from $1,950 2023-09-20
Dgx H100 Firmware HIGH 8.8
CVE-2023-31012

NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this …

Fix: 23.08.18+
Fix from $1,950 2023-09-20
Dgx H100 Firmware HIGH 8.8
CVE-2023-31010

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerabili…

Fix: 23.08.18+
Fix from $1,950 2023-09-20
Dgx H100 Firmware CRITICAL 9.8
CVE-2023-25534

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerabili…

Fix: 23.08.18+
Fix from $2,300 2023-09-20
Dgx H100 Firmware HIGH 7.8
CVE-2023-31008

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerabili…

Fix: 23.08.18+
Fix from $1,950 2023-09-20
Dgx H100 Firmware CRITICAL 9.8
CVE-2023-31009

NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this…

Fix: 23.08.18+
Fix from $2,300 2023-09-20
Dgx H100 Firmware CRITICAL 9.8
CVE-2023-25533

NVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of this vulne…

Fix: 23.08.18+
Fix from $2,300 2023-09-20
Dgx H100 Firmware CRITICAL 9.8
CVE-2023-25530

NVIDIA DGX H100 BMC contains a vulnerability in the KVM service, where an attacker may cause improper input validation. A successful exploit of this …

Fix: 23.08.18+
Fix from $2,300 2023-09-20
Cmc HIGH 7.5
CVE-2023-32649

A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Int…

Fix: 22.6.3 / 23.1.0+
Fix from $1,950 2023-09-19
Vault MEDIUM 6.8
CVE-2023-4680

HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption dis…

Fix: 1.12.11 / 1.13.7+
Fix from $1,600 2023-09-15
Commons Compress MEDIUM 5.5
CVE-2023-42503

Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Common…

Fix: 1.24.0+
Fix from $1,600 2023-09-14
Pm43 Firmware CRITICAL 9.8
CVE-2023-3710EPSS 33%

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 …

Mitigation only
Fix from $2,300 2023-09-12
Zoom HIGH 7.5
CVE-2023-39208

Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service vi…

Fix: 5.15.10+
Fix from $1,950 2023-09-12
Azure Hdinsight HIGH 7.2
CVE-2023-38156

Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-09-12
365 Apps HIGH 7.3
CVE-2023-36762

Microsoft Word Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-09-12
365 Apps MEDIUM 6.5
CVE-2023-36761 KEVEPSS 19%

Microsoft Word Information Disclosure Vulnerability

Patch available
Fix from $1,600 2023-09-12
Azure Kubernetes Service CRITICAL 9.8
CVE-2023-29332

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2023-09-12
Factorytalk View CRITICAL 9.8
CVE-2023-2071EPSS 11%

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t…

Fix: after 13.0
Fix from $2,300 2023-09-12
Magento Open Source HIGH 7.2
CVE-2022-24093

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of…

Fix: 2.3.7 / 2.4.3+
Fix from $1,950 2023-09-12
Ux Autocomplete MEDIUM 6.5
CVE-2023-41336

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity …

Fix: 2.11.2+
Fix from $1,600 2023-09-11
Tolgee MEDIUM 5.4
CVE-2023-41316

Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the …

Fix: 3.29.2+
Fix from $1,600 2023-09-07
Ipados HIGH 7.8
CVE-2023-41061 KEV

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attac…

Fix: 9.6.2 / 16.6.1+
Fix from $1,950 2023-09-07
Superset MEDIUM 6.5
CVE-2023-39265EPSS 84%

Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+p…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Magento HIGH 7.2
CVE-2021-36021

Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper input validation vulnerability withi…

Fix: 2.3.7 / 2.4.2+
Fix from $1,950 2023-09-06