Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.7 CVE-2023-20634 In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System e… Android Mitigation only Fix from $1,6002023-03-07 HIGH 8.6 CVE-2022-4904 A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbit… Software Collections 1.19.0+ Fix from $1,9502023-03-06 MEDIUM 5.3 CVE-2021-36402 In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 HIGH 8.8 CVE-2022-3294 Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node ob… Kubernetes 1.22.16 / 1.23.14+ Fix from $1,9502023-03-01 HIGH 7.5 CVE-2023-26281 IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. I… HTTP Server Patch available Fix from $1,9502023-03-01 HIGH 7.2 CVE-2023-20009 A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow… Email Security Appliance 12.5.3-041 / 12.8.1-021+ Fix from $1,9502023-03-01 MEDIUM 5.3 CVE-2022-20952 A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA… Asyncos 14.0.4+ Fix from $1,6002023-03-01 HIGH 7.5 CVE-2022-40237 IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel synchronization logic. IBM X-Fo… Mq For Hpe Nonstop Patch available Fix from $1,9502023-02-27 CRITICAL 9.8 CVE-2021-35370 An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. Imcat No fix yet Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25691 Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1… Apache Airflow Providers Google 8.10.0+ Fix from $2,3002023-02-24 HIGH 7.5 CVE-2023-25692 Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.1… Apache Airflow Providers Google 8.10.0+ Fix from $1,9502023-02-24 CRITICAL 9.8 CVE-2023-25693 Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. Apache Airflow Providers Apache Sqoop 3.1.1+ Fix from $2,3002023-02-24 CRITICAL 9.8 CVE-2023-25696 Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. Apache Airflow Providers Apache Hive 5.1.3+ Fix from $2,3002023-02-24 MEDIUM 6.1 CVE-2023-0867 Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could all… Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.1 CVE-2023-0868 Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session … Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.1 CVE-2023-0869 Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session inform… Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 HIGH 7.5 CVE-2022-46303 Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Mana… Checkmk Mitigation only Fix from $1,9502023-02-20 HIGH 8.8 CVE-2022-46836 PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta… Checkmk No fix yet Fix from $1,9502023-02-20 HIGH 7.8 CVE-2022-47909 Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions o… Checkmk No fix yet Fix from $1,9502023-02-20 HIGH 7.8 CVE-2023-22239 After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbit… After Effects 22.6.4 / 23.2.0+ Fix from $1,9502023-02-17 HIGH 7.8 CVE-2023-22228 Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a… Bridge 12.0.4 / 13.0.2+ Fix from $1,9502023-02-17 HIGH 7.8 CVE-2023-21574 Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary … Photoshop 23.5.4 / 24.1.1+ Fix from $1,9502023-02-17 HIGH 7.8 CVE-2023-21621 FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary … Framemaker after 2020.0.4 Fix from $1,9502023-02-17 HIGH 7.5 CVE-2022-43929 IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-F… Db2 Patch available Fix from $1,9502023-02-17 HIGH 7.5 CVE-2023-24329EPSS 20% An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with bl… Python 3.7.17 / 3.8.17+ Fix from $1,9502023-02-17 HIGH 7.8 CVE-2022-33190 Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of pr… System Usage Report 2.4.8902+ Fix from $1,9502023-02-16 CRITICAL 9.8 CVE-2022-33964 Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of … System Usage Report 2.4.8902+ Fix from $2,3002023-02-16 MEDIUM 6.5 CVE-2022-29494 Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated us… Openbmc Mitigation only Fix from $1,6002023-02-16 HIGH 7.0 CVE-2022-26837 Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege… Xeon Gold 5317 Firmware Mitigation only Fix from $1,9502023-02-16 HIGH 7.5 CVE-2023-24807 Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expre… Undici 5.19.1+ Fix from $1,9502023-02-16