Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Smart Clock Essential With Alexa Built In Firmware HIGH 8.8
CVE-2023-0896

A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with l…

Fix: 90+
Fix from $1,950 2023-05-01
Db2 HIGH 7.5
CVE-2023-26021

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when com…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 HIGH 7.5
CVE-2023-26022

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory …

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 MEDIUM 5.9
CVE-2023-25930

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, …

Fix: 11.1.4 / 11.5.8+
Fix from $1,600 2023-04-28
Db2 HIGH 7.5
CVE-2023-27555

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinit…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-28
Db2 HIGH 7.5
CVE-2023-29255

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compi…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-27
Db2 HIGH 7.5
CVE-2023-27559

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Fix: 11.1.4 / 11.5.8+
Fix from $1,950 2023-04-26
Drupal HIGH 7.5
CVE-2022-25273

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co…

Fix: 9.2.18 / 9.3.12+
Fix from $1,950 2023-04-26
Cltphp HIGH 8.1
CVE-2023-30269

CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.

Fix: after 6.0
Fix from $1,950 2023-04-26
Fedora MEDIUM 6.5
CVE-2023-29530

Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0…

Fix: 1.9.1 / 2.4.5+
Fix from $1,600 2023-04-24
3rsb015bz Firmware HIGH 7.5
CVE-2023-29780

Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send malicious Zigbee messages to a v…

No fix yet
Fix from $1,950 2023-04-24
Usg Flex 100 Firmware HIGH 8.1
CVE-2023-22916

The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W)…

Fix: after 5.35
Fix from $1,950 2023-04-24
White Rabbit Switch Firmware CRITICAL 9.8
CVE-2023-22581

White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web applicat…

Fix: after 6.0.1
Fix from $2,300 2023-04-24
Onos CRITICAL 9.8
CVE-2022-29606

An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Imprope…

No fix yet
Fix from $2,300 2023-04-20
Android HIGH 7.8
CVE-2023-21092

In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App …

Patch available
Fix from $1,950 2023-04-19
Fedora MEDIUM 5.3
CVE-2023-27043

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 heade…

Fix: 3.8.20 / 3.9.20+
Fix from $1,600 2023-04-19
Insighthome Firmware HIGH 8.8
CVE-2023-29410

A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on …

Fix: 1.16+
Fix from $1,950 2023-04-18
Redis MEDIUM 6.5
CVE-2023-28856

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash f…

Fix: 6.0.19 / 6.2.12+
Fix from $1,600 2023-04-18
Junos MEDIUM 6.5
CVE-2023-28981

An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attack…

Mitigation only
Fix from $1,600 2023-04-17
Contracts HIGH 8.8
CVE-2023-30542

OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBrav…

Fix: 4.8.3+
Fix from $1,950 2023-04-16
Snowflake Jdbc HIGH 8.8
CVE-2023-30535

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake …

Fix: 3.13.29+
Fix from $1,950 2023-04-14
Mdm8207 Firmware CRITICAL 9.8
CVE-2022-33211

memory corruption in modem due to improper check while calculating size of serialized CoAP message

Mitigation only
Fix from $2,300 2023-04-13
Substance 3d Stager HIGH 7.8
CVE-2023-26388

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code e…

Fix: after 2.0.1
Fix from $1,950 2023-04-12
Acrobat HIGH 7.8
CVE-2023-26407

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability th…

Fix: after 23.001.20093
Fix from $1,950 2023-04-12
Acrobat HIGH 7.8
CVE-2023-26405

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability th…

Fix: after 23.001.20093
Fix from $1,950 2023-04-12
Odbc HIGH 7.8
CVE-2023-28304

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

Fix: 17.10.3.1 / 18.2.1.1+
Fix from $1,950 2023-04-11
Raw Image Extension HIGH 7.8
CVE-2023-28291

Raw Image Extension Remote Code Execution Vulnerability

Fix: 2.0.60612.0 / 2.1.60611.0+
Fix from $1,950 2023-04-11
Windows 10 1607 HIGH 7.5
CVE-2023-28302EPSS 93%

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Fix: 10.0.14393.5850 / 10.0.17763.4252+
Fix from $1,950 2023-04-11
Windows 10 1809 HIGH 7.8
CVE-2023-28274EPSS 7%

Windows Win32k Elevation of Privilege Vulnerability

Fix: 10.0.17763.4252 / 10.0.19042.2846+
Fix from $1,950 2023-04-11
Visual Studio Code HIGH 7.8
CVE-2023-24893

Visual Studio Code Remote Code Execution Vulnerability

Fix: 1.77.0+
Fix from $1,950 2023-04-11