Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2022-26047 Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user… Killer Wifi Software 2.2.14.22176 / 3.1122.3158+ Fix from $1,6002022-11-11 MEDIUM 6.7 CVE-2022-26006 Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege… Core I5 7640x Firmware Mitigation only Fix from $1,6002022-11-11 MEDIUM 6.5 CVE-2021-26251 Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of servic… Openvino 2021.4.2+ Fix from $1,6002022-11-11 MEDIUM 6.7 CVE-2021-0185 Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a privileged user to potentiall… M10jnp2sb Firmware 7.216+ Fix from $1,6002022-11-10 HIGH 7.8 CVE-2022-39880 Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code exec… Android Mitigation only Fix from $1,9502022-11-09 CRITICAL 9.1 CVE-2022-39881 Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of… Exynos Firmware Mitigation only Fix from $2,3002022-11-09 HIGH 8.1 CVE-2022-39306 Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper In… Grafana 8.5.15 / 9.2.4+ Fix from $1,9502022-11-09 MEDIUM 5.3 CVE-2022-44553 The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successfu… Harmonyos Mitigation only Fix from $1,6002022-11-09 HIGH 7.5 CVE-2022-27674 Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows … Amd Uprof 3.6.449 / 3.6.549+ Fix from $1,9502022-11-09 HIGH 7.5 CVE-2022-23831 Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kerne… Amd Uprof 3.6.449 / 3.6.549+ Fix from $1,9502022-11-09 HIGH 7.5 CVE-2022-45060 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may in… Fedora 6.0.11 / 7.1.2+ Fix from $1,9502022-11-09 HIGH 8.7 CVE-2022-41214 Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a … Netweaver Application Server Abap Mitigation only Fix from $1,9502022-11-08 MEDIUM 5.5 CVE-2022-20457 In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This … Android Mitigation only Fix from $1,6002022-11-08 HIGH 7.5 CVE-2022-44556 Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502022-11-08 HIGH 8.8 CVE-2022-43439 A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1… 7kg9501 0aa01 2aa1 Firmware 2.50+ Fix from $1,9502022-11-08 HIGH 8.8 CVE-2022-43545 A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICA… 7kg9501 0aa01 2aa1 Firmware 2.50+ Fix from $1,9502022-11-08 HIGH 8.8 CVE-2022-43546 A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICA… 7kg9501 0aa01 2aa1 Firmware 2.50+ Fix from $1,9502022-11-08 HIGH 8.8 CVE-2022-43565 In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker byp… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 HIGH 8.0 CVE-2022-43566 In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 MEDIUM 5.4 CVE-2022-43562 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 HIGH 8.8 CVE-2022-43563 In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 MEDIUM 5.5 CVE-2022-43449 OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious applicat… Openharmony after 3.1.2 Fix from $1,6002022-11-03 MEDIUM 6.5 CVE-2022-40235 "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input val… Infosphere Information Server Patch available Fix from $1,6002022-11-03 MEDIUM 5.5 CVE-2022-40276 Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown fi… Zettlr No fix yet Fix from $1,6002022-11-03 MEDIUM 5.5 CVE-2022-3675 Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the… Fedora Coreos 37.20221031.1.0+ Fix from $1,6002022-11-03 MEDIUM 6.5 CVE-2022-39376 GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk feat… Glpi 10.0.4+ Fix from $1,6002022-11-03 HIGH 7.5 CVE-2022-3181 An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause t… Vtscada after 12.0.38 Fix from $1,9502022-11-02 CRITICAL 9.8 CVE-2022-39353 xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses XML that is not well-form… Debian Linux 0.6.0 / 0.7.7+ Fix from $2,3002022-11-02 HIGH 8.8 CVE-2022-3656 Insufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system restrictions via … Chrome 107.0.5304.62+ Fix from $1,9502022-11-01 HIGH 7.8 CVE-2022-42800 This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadO… Ipados 9.1 / 11.7.1+ Fix from $1,9502022-11-01