Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Control For Beaglebone Sl MEDIUM 6.5
CVE-2023-37546

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…

Fix: 4.10.0.0+
Fix from $1,600 2023-08-03
Control For Beaglebone Sl MEDIUM 6.5
CVE-2023-37547

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…

Fix: 4.10.0.0+
Fix from $1,600 2023-08-03
Control For Beaglebone Sl MEDIUM 6.5
CVE-2023-37548

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…

Fix: 4.10.0.0+
Fix from $1,600 2023-08-03
Control For Beaglebone Sl MEDIUM 6.5
CVE-2023-37545

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with in…

Fix: 4.10.0.0+
Fix from $1,600 2023-08-03
Chrome MEDIUM 6.5
CVE-2022-4911

Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a cr…

Fix: 106.0.5249.62+
Fix from $1,600 2023-07-29
Chrome MEDIUM 6.5
CVE-2022-4925

Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via m…

Fix: 97.0.4692.71+
Fix from $1,600 2023-07-29
Crossplane CRITICAL 9.8
CVE-2023-38495

Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Cr…

Fix: 1.11.5 / 1.12.3+
Fix from $2,300 2023-07-27
Xperiencentral HIGH 7.5
CVE-2022-43713

Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data input because form validation cou…

Fix: after 10.35.0
Fix from $1,950 2023-07-26
Gaia Portal HIGH 7.2
CVE-2023-28130EPSS 21%

Local user may lead to privilege escalation using Gaia Portal hostnames page.

No fix yet
Fix from $1,950 2023-07-26
Rtu500 Firmware HIGH 7.5
CVE-2022-2502

A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be e…

Mitigation only
Fix from $1,950 2023-07-26
Tdengine MEDIUM 6.5
CVE-2023-38502

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF…

Fix: 3.0.7.1+
Fix from $1,600 2023-07-25
Envoy MEDIUM 5.3
CVE-2023-35944

Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some inter…

Fix: 1.23.12 / 1.24.10+
Fix from $1,600 2023-07-25
Otrs HIGH 8.8
CVE-2023-38060

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I…

Fix: 7.0.45 / 8.0.35+
Fix from $1,950 2023-07-24
Survey MEDIUM 5.4
CVE-2023-38057

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject …

Fix: 7.0.32 / 8.0.13+
Fix from $1,600 2023-07-24
Opendds HIGH 7.5
CVE-2023-37915

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a ma…

No fix yet
Fix from $1,950 2023-07-21
Netscaler Application Delivery Controller MEDIUM 6.1
CVE-2023-3466

Reflected Cross-Site Scripting (XSS)

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $1,600 2023-07-19
Security Guardium MEDIUM 6.5
CVE-2022-43908

IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903.

Patch available
Fix from $1,600 2023-07-19
Mq HIGH 7.5
CVE-2023-28513

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configuration…

Patch available
Fix from $1,950 2023-07-19
Wolfssl HIGH 8.8
CVE-2023-3724

If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default pr…

Fix: 5.6.2+
Fix from $1,950 2023-07-17
Edge Chromium MEDIUM 6.3
CVE-2023-36888

Microsoft Edge for Android (Chromium-based) Tampering Vulnerability

Fix: 114.0.1823.82+
Fix from $1,600 2023-07-14
Jami MEDIUM 5.5
CVE-2023-3433

The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the fi…

Patch available
Fix from $1,600 2023-07-14
Jami MEDIUM 5.4
CVE-2023-3434

Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. This allows an attacker to se…

Patch available
Fix from $1,600 2023-07-14
Alaris 8015 Pcu Firmware MEDIUM 5.7
CVE-2023-30559

The firmware update package for the wireless card is not properly signed and can be modified.

Fix: after 12.1.3
Fix from $1,600 2023-07-13
Zabbix HIGH 7.5
CVE-2023-29451

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.

Fix: after 6.4.4
Fix from $1,950 2023-07-13
Zabbix MEDIUM 5.4
CVE-2023-29452EPSS 64%

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Oth…

Fix: after 6.0.17
Fix from $1,600 2023-07-13
Frontend MEDIUM 5.4
CVE-2023-29454

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the applicat…

Fix: after 6.0.16
Fix from $1,600 2023-07-13
Frontend MEDIUM 6.1
CVE-2023-29455

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser…

Fix: after 5.0.33
Fix from $1,600 2023-07-13
Frontend MEDIUM 5.4
CVE-2023-29456

URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL…

Fix: after 6.4.3
Fix from $1,600 2023-07-13
Frontend MEDIUM 6.1
CVE-2023-29457

Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through …

Fix: after 6.0.17
Fix from $1,600 2023-07-13
Apache Airflow Providers Apache Hive HIGH 8.8
CVE-2023-37415

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before …

Fix: 6.1.2+
Fix from $1,950 2023-07-13