Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2023-22470 Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A databas… Deck 1.6.5 / 1.7.3+ Fix from $1,6002023-01-14 HIGH 7.8 CVE-2023-21596 Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrar… Incopy after 17.4 Fix from $1,9502023-01-13 HIGH 7.8 CVE-2023-21588 Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitra… Indesign after 17.4 Fix from $1,9502023-01-13 MEDIUM 5.4 CVE-2023-22491 Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior t… Gatsby 5.25.1+ Fix from $1,6002023-01-13 HIGH 8.8 CVE-2022-46372 Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command executi… Ar7088h A Firmware after 16.10.3 Fix from $1,9502023-01-12 HIGH 8.0 CVE-2022-4428 support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching … Warp after 2022.10.106.0 Fix from $1,9502023-01-11 HIGH 8.8 CVE-2023-22952 KEVEPSS 80% In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. Sugarcrm 11.0.5 / 12.0.2+ Fix from $1,9502023-01-11 MEDIUM 5.3 CVE-2023-20532 Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. Epyc 7h12 Firmware Mitigation only Fix from $1,6002023-01-11 MEDIUM 6.1 CVE-2021-46767 Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a los… Romepi Firmware 1.0.0.d / 1.0.0.6+ Fix from $1,6002023-01-11 MEDIUM 5.3 CVE-2022-23814 Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential com… Milanpi Sp3 Firmware 1.0.0.9+ Fix from $1,6002023-01-11 HIGH 7.5 CVE-2023-20522 Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service. Milanpi Firmware 1.0.0.5 / 100d+ Fix from $1,9502023-01-11 MEDIUM 6.5 CVE-2023-20525 Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register po… Epyc 7h12 Firmware Mitigation only Fix from $1,6002023-01-11 MEDIUM 6.5 CVE-2023-20527 Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial… Epyc 7h12 Firmware Mitigation only Fix from $1,6002023-01-11 HIGH 7.5 CVE-2023-20530 Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service. Epyc 7003 Firmware Mitigation only Fix from $1,9502023-01-11 MEDIUM 5.5 CVE-2021-26404 Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. Epyc 7003 Firmware Mitigation only Fix from $1,6002023-01-11 HIGH 7.8 CVE-2021-26316 Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in poten… Epyc 7h12 Firmware Mitigation only Fix from $1,9502023-01-11 MEDIUM 5.3 CVE-2023-22963 The personnummer implementation before 3.0.3 for Dart mishandles numbers in which the last four digits match the ^000[0-9]$ regular expression. Personnummer 3.0.3+ Fix from $1,6002023-01-11 HIGH 7.8 CVE-2023-21767 Windows Overlay Filter Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21749 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 MEDIUM 5.5 CVE-2023-21559 Windows Cryptographic Information Disclosure Vulnerability Windows 10 1809 No fix yet Fix from $1,6002023-01-10 MEDIUM 5.5 CVE-2023-21550 Windows Cryptographic Information Disclosure Vulnerability Windows 10 1809 No fix yet Fix from $1,6002023-01-10 HIGH 7.8 CVE-2023-21558 Windows Error Reporting Service Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502023-01-10 MEDIUM 5.5 CVE-2023-21540 Windows Cryptographic Information Disclosure Vulnerability Windows 10 1809 No fix yet Fix from $1,6002023-01-10 MEDIUM 6.5 CVE-2023-0139 Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass downlo… Chrome 109.0.5414.74+ Fix from $1,6002023-01-10 MEDIUM 6.5 CVE-2023-22898 workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive … Pandora 1.3.1+ Fix from $1,6002023-01-10 HIGH 7.8 CVE-2022-33300 Memory corruption in Automotive Android OS due to improper input validation. Qam8295p Firmware No fix yet Fix from $1,9502023-01-09 MEDIUM 6.5 CVE-2022-23549 Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-p… Discourse 2.8.14+ Fix from $1,6002023-01-05 MEDIUM 5.3 CVE-2023-22465 Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-… Http4s 0.21.34 / 0.22.15+ Fix from $1,6002023-01-04 CRITICAL 9.8 CVE-2022-45875 Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects… Dolphinscheduler 3.0.2+ Fix from $2,3002023-01-04 HIGH 7.5 CVE-2023-22460 go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C… Go Ipld Prime 0.19.0+ Fix from $1,9502023-01-04