Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2022-22658 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 16.0.3. Processing a maliciously crafted email mes… Iphone Os 16.0.3+ Fix from $1,6002022-11-01 HIGH 7.5 CVE-2022-25885 The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with… Muhammara 2.6.0+ Fix from $1,9502022-11-01 MEDIUM 5.4 CVE-2022-39017 Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce… Hubshare 3.3.10.9+ Fix from $1,6002022-10-31 HIGH 8.8 CVE-2022-39016 Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF u… Hubshare 3.3.10.9+ Fix from $1,9502022-10-31 CRITICAL 9.6 CVE-2022-28763 The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a … Meetings 5.12.2+ Fix from $2,3002022-10-31 HIGH 8.8 CVE-2022-0073EPSS 9% Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injecti… Openlitespeed after 1.7.16.1 Fix from $1,9502022-10-27 CRITICAL 9.8 CVE-2022-3095 The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG U… Dart Software Development Kit 2.18.0 / 3.3.3+ Fix from $2,3002022-10-27 HIGH 8.8 CVE-2022-39361 Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) c… Metabase 0.41.9 / 0.42.6+ Fix from $1,9502022-10-26 CRITICAL 9.8 CVE-2022-42468 Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa… Flume after 1.10.1 Fix from $2,3002022-10-26 HIGH 8.1 CVE-2022-20822 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read a… Identity Services Engine Mitigation only Fix from $1,9502022-10-26 HIGH 7.2 CVE-2022-33178 A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitr… Fabric Operating System 9.0.0+ Fix from $1,9502022-10-25 HIGH 7.8 CVE-2022-38435 Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result i… Illustrator after 26.4 Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2022-39312 Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql dat… Dataease 1.15.2+ Fix from $2,3002022-10-25 MEDIUM 6.5 CVE-2022-3676 In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlin… Openj9 0.35.0+ Fix from $1,6002022-10-24 MEDIUM 6.5 CVE-2021-44769 An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition… Iac Ast2500a Firmware Mitigation only Fix from $1,6002022-10-24 MEDIUM 5.5 CVE-2022-39259 jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prior to 1.4.5 are subject to a D… Jadx 1.4.5+ Fix from $1,6002022-10-21 MEDIUM 6.5 CVE-2022-41813 In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or … Big Ip Advanced Firewall Manager 14.1.5 / 15.1.6.1+ Fix from $1,6002022-10-19 HIGH 7.5 CVE-2022-41836 When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd proce… Big Ip Advanced Web Application Firewall 15.1.7 / 16.1.3.1+ Fix from $1,9502022-10-19 HIGH 8.8 CVE-2022-1414 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject s… 3scale Api Management Mitigation only Fix from $1,9502022-10-19 HIGH 7.5 CVE-2022-22247 An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows a network-based unauthentica… Junos Os Evolved Mitigation only Fix from $1,9502022-10-18 HIGH 7.5 CVE-2022-22228 An Improper Validation of Specified Type of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an attacker … Junos Mitigation only Fix from $1,9502022-10-18 MEDIUM 6.5 CVE-2022-22230 An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent … Junos Mitigation only Fix from $1,6002022-10-18 CRITICAL 9.8 CVE-2022-22241 An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data w… Junos 19.1+ Fix from $2,3002022-10-18 HIGH 7.5 CVE-2022-22192 An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a netw… Junos Os Evolved Mitigation only Fix from $1,9502022-10-18 HIGH 7.5 CVE-2022-22201 An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos… Junos 19.4+ Fix from $1,9502022-10-18 HIGH 7.5 CVE-2022-22223 On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (PHP) nodes with link aggregati… Junos 15.1+ Fix from $1,9502022-10-18 CRITICAL 9.8 CVE-2022-23770 This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remot… Smart Wing Cms 19051+ Fix from $2,3002022-10-17 HIGH 7.5 CVE-2022-42340EPSS 34% Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could re… Coldfusion Mitigation only Fix from $1,9502022-10-14 HIGH 7.5 CVE-2022-38985 The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality. Emui Mitigation only Fix from $1,9502022-10-14 HIGH 7.5 CVE-2022-3171 A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service a… Google Protobuf 3.16.3 / 3.19.6+ Fix from $1,9502022-10-12