Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.1 CVE-2022-32482 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit thi… Alienware M15 R6 Firmware 1.7.3 / 1.10.0+ Fix from $1,6002023-02-01 HIGH 7.8 CVE-2022-34443 Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attacker could… Rugged Control Center after 4.4.134 Fix from $1,9502023-02-01 MEDIUM 6.5 CVE-2022-44644 In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files b… Linkis after 1.3.0 Fix from $1,6002023-01-31 CRITICAL 9.8 CVE-2022-39060 ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vul… Megaservisignadapter 1.0.22.1004+ Fix from $2,3002023-01-31 MEDIUM 6.7 CVE-2022-34885 An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary co… Mr2600 Firmware 1.0.18+ Fix from $1,6002023-01-30 HIGH 7.8 CVE-2022-45770 Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation. Adguard 7.12+ Fix from $1,9502023-01-26 MEDIUM 5.7 CVE-2023-24493 A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticat… Tenable.sc after 5.23.1 Fix from $1,6002023-01-26 HIGH 8.1 CVE-2023-0284 Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Chec… Checkmk 2.0.0+ Fix from $1,9502023-01-26 MEDIUM 6.3 CVE-2023-0229 A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged … Openshift Mitigation only Fix from $1,6002023-01-26 HIGH 7.5 CVE-2022-47100 A vulnerability in Sengled Smart bulb 0x0000024 allows attackers to arbitrarily perform a factory reset on the device via a crafted IEEE 802.15.4 fra… Es21 N1eaw Firmware No fix yet Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-3736EPSS 49% BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the … Bind 9.16.37 / 9.18.11+ Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2023-23560EPSS 14% In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. B2236 Firmware No fix yet Fix from $2,3002023-01-23 MEDIUM 5.3 CVE-2021-43448 ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the na… Server after 7.0.0.49 Fix from $1,6002023-01-23 HIGH 7.5 CVE-2023-0434 Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40. Pyload after 0.4.9 Fix from $1,9502023-01-22 MEDIUM 5.3 CVE-2022-41733 IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. I… Infosphere Information Server 11.7.1.4+ Fix from $1,6002023-01-20 HIGH 7.2 CVE-2023-20045 A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote… Rv160 Vpn Router Firmware 1.0.01.04+ Fix from $1,9502023-01-20 HIGH 8.6 CVE-2023-20020 A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services … Broadworks Application Delivery Platform Device Management 23.0.1075.ap384245 / 2022.11_1.273+ Fix from $1,9502023-01-20 HIGH 7.2 CVE-2023-20026 A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an aut… Rv016 Firmware Mitigation only Fix from $1,9502023-01-20 HIGH 7.8 CVE-2023-21607 Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an Improper Input… Acrobat Dc after 22.003.20282 Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2022-47966 KEVEPSS 100% Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xm… Manageengine Access Manager Plus 4.3 / 5.1+ Fix from $2,3002023-01-18 HIGH 7.8 CVE-2022-32490 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi… Edge Gateway 3000 Firmware 1.9.0 / 1.15.0+ Fix from $1,9502023-01-18 HIGH 7.5 CVE-2022-34393 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi… G5 Se 5505 Firmware 1.5.0 / 1.8.0+ Fix from $1,9502023-01-18 HIGH 7.8 CVE-2022-34460 Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulner… G5 Se 5505 Firmware 1.5.0 / 1.8.0+ Fix from $1,9502023-01-18 MEDIUM 6.5 CVE-2022-47917 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user in… Real Time Location System Studio after 2.6.2 Fix from $1,6002023-01-18 MEDIUM 6.5 CVE-2022-43455 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user in… Real Time Location System Studio after 2.6.2 Fix from $1,6002023-01-18 HIGH 7.5 CVE-2023-22734 Shopware is an open source commerce platform based on Symfony Framework and Vue js. The newsletter double opt-in validation was not checked properly,… Shopware 6.4.18.1+ Fix from $1,9502023-01-17 HIGH 7.5 CVE-2023-22730 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item mu… Shopware 6.4.18.1+ Fix from $1,9502023-01-17 MEDIUM 6.5 CVE-2022-41861 A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. Freeradius after 3.0.25 Fix from $1,6002023-01-17 CRITICAL 9.8 CVE-2023-0299 Improper Input Validation in GitHub repository publify/publify prior to 9.2.10. Publify 9.2.10+ Fix from $2,3002023-01-14 CRITICAL 9.8 CVE-2023-22496EPSS 36% Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming c… Netdata 1.37.0+ Fix from $2,3002023-01-14