Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.8
CVE-2023-30712

Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

Mitigation only
Fix from $1,950 2023-09-06
Fedora HIGH 8.8
CVE-2023-39357

Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type…

No fix yet
Fix from $1,950 2023-09-05
Airwave HIGH 7.2
CVE-2015-2202

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

Fix: 7.7.14.2 / 8.0.7+
Fix from $1,950 2023-09-05
Oas Platform MEDIUM 6.5
CVE-2023-34317

An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072.…

No fix yet
Fix from $1,600 2023-09-05
Axis CRITICAL 9.8
CVE-2023-40743

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S…

Fix: 2023-08-01+
Fix from $2,300 2023-09-05
Security Guardium MEDIUM 6.5
CVE-2022-43903

IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. I…

Patch available
Fix from $1,600 2023-09-05
Yocto MEDIUM 6.7
CVE-2023-32811

In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2023-09-04
Android HIGH 7.5
CVE-2023-33914

In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosur…

No fix yet
Fix from $1,950 2023-09-04
Memos HIGH 7.5
CVE-2023-4698

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

Fix: 0.13.2+
Fix from $1,950 2023-09-01
Junos HIGH 7.5
CVE-2023-4481EPSS 15%

An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthent…

Fix: 20.4+
Fix from $1,950 2023-09-01
Cloud Manager CRITICAL 9.8
CVE-2023-41746

Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.2308…

Fix: 6.2.23089.203+
Fix from $2,300 2023-08-31
Cloud Manager CRITICAL 9.8
CVE-2023-41748

Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.2308…

Fix: 6.2.23089.203+
Fix from $2,300 2023-08-31
Archive HIGH 7.8
CVE-2023-39137

An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.

No fix yet
Fix from $1,950 2023-08-30
Stormshield Network Security HIGH 7.5
CVE-2023-26095

ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.

Fix: 4.6.3+
Fix from $1,950 2023-08-28
Airflow Sqoop Provider HIGH 8.8
CVE-2023-27604

Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh…

Fix: 4.0.0+
Fix from $1,950 2023-08-28
Ac23 Firmware HIGH 8.8
CVE-2023-40797

In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack…

No fix yet
Fix from $1,950 2023-08-25
Ac23 Firmware HIGH 8.8
CVE-2023-40798

In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post…

No fix yet
Fix from $1,950 2023-08-25
Ac23 Firmware HIGH 8.8
CVE-2023-40800

The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability …

No fix yet
Fix from $1,950 2023-08-25
Ac23 HIGH 8.8
CVE-2023-40801

The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_…

No fix yet
Fix from $1,950 2023-08-25
Cp Vnr 3104 Firmware HIGH 7.5
CVE-2023-3705

The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthent…

Patch available
Fix from $1,950 2023-08-24
Cp Uvr 1601e1 Hc Firmware MEDIUM 5.3
CVE-2023-3704

The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An un…

Fix: 4.000.00at008.0.0.r20230302+
Fix from $1,600 2023-08-24
Nx Os MEDIUM 6.5
CVE-2023-20168

A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affec…

Mitigation only
Fix from $1,600 2023-08-23
Nx Os HIGH 7.4
CVE-2023-20169

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches a…

Mitigation only
Fix from $1,950 2023-08-23
Ak Sm 800a Firmware HIGH 8.8
CVE-2023-25915

Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.

Fix: after 3.3
Fix from $1,950 2023-08-21
Mediawiki MEDIUM 5.3
CVE-2023-36674

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possi…

Fix: 1.35.11 / 1.38.7+
Fix from $1,600 2023-08-20
Inure MEDIUM 5.5
CVE-2023-4435

Improper Input Validation in GitHub repository hamza417/inure prior to build88.

Patch available
Fix from $1,600 2023-08-20
Rubygems.org HIGH 7.5
CVE-2023-40165

rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any upl…

Fix: 2023-08-14+
Fix from $1,950 2023-08-17
Thinmanager Thinserver HIGH 7.5
CVE-2023-2914EPSS 40%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the…

Fix: after 13.0.2
Fix from $1,950 2023-08-17
Thinmanager Thinserver CRITICAL 9.1
CVE-2023-2915EPSS 84%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path tr…

Fix: after 13.0.2
Fix from $2,300 2023-08-17
Thinmanager Thinserver CRITICAL 9.8
CVE-2023-2917EPSS 72%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a pat…

Fix: after 13.0.2
Fix from $2,300 2023-08-17