Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2021-44545 Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable… Killer Ac 1550 Firmware 3.1122.1105 / 22.120+ Fix from $1,6002022-08-18 MEDIUM 5.3 CVE-2022-36023 Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client ap… Fabric 2.4.6+ Fix from $1,6002022-08-18 MEDIUM 5.5 CVE-2022-2868 libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is ab… Fedora 4.4.0+ Fix from $1,6002022-08-17 HIGH 7.5 CVE-2021-26639 This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this v… Smart Wing Cms Mitigation only Fix from $1,9502022-08-17 HIGH 7.2 CVE-2020-1756 In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. Moodle 3.5.11 / 3.6.9+ Fix from $1,9502022-08-16 HIGH 8.8 CVE-2022-35239 The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficien… Sv Cpt Mc310f Firmware 7.24+ Fix from $1,9502022-08-16 MEDIUM 6.5 CVE-2022-24952 Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an invalid sequence… Eternal Terminal 6.2.0+ Fix from $1,6002022-08-16 MEDIUM 6.5 CVE-2022-2618 Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrict… Chrome 104.0.5112.79+ Fix from $1,6002022-08-12 MEDIUM 6.7 CVE-2022-20314 In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could lead to local escalation of pri… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 5.0 CVE-2022-20266 In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to impro… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 6.1 CVE-2022-28755 The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a… Virtual Desktop Infrastructure 5.10.7 / 5.11.0+ Fix from $1,6002022-08-11 HIGH 7.8 CVE-2022-35666EPSS 7% Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an Improper Input… Acrobat Dc after 22.001.20169 Fix from $1,9502022-08-11 MEDIUM 5.5 CVE-2022-35668 Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an Improper Input… Acrobat Dc after 22.001.20169 Fix from $1,6002022-08-11 CRITICAL 9.8 CVE-2021-22289 Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network a… Studio Mitigation only Fix from $2,3002022-08-11 MEDIUM 5.5 CVE-2022-20355 In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service… Android Patch available Fix from $1,6002022-08-10 HIGH 7.8 CVE-2022-20356 In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improp… Android Patch available Fix from $1,9502022-08-10 MEDIUM 5.5 CVE-2022-20350 In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app… Android Patch available Fix from $1,6002022-08-10 MEDIUM 5.5 CVE-2022-20353 In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to… Android Patch available Fix from $1,6002022-08-10 CRITICAL 9.8 CVE-2022-20842 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe… Rv340 Firmware 1.0.03.28+ Fix from $2,3002022-08-10 CRITICAL 9.0 CVE-2022-20841 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exe… Rv160 Firmware 1.0.01.05 / 1.0.03.26+ Fix from $2,3002022-08-10 HIGH 7.5 CVE-2021-37150 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-28129 Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue af… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31778 Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. Thi… Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31779 Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects … Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-31780 Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects … Traffic Server after 9.1.2 Fix from $1,9502022-08-10 HIGH 7.8 CVE-2022-35773 Azure RTOS GUIX Studio Remote Code Execution Vulnerability Azure Real Time Operating System Guix Studio Mitigation only Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-35724 It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications usin… Avro 0.14.0+ Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-36125 It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust … Avro 0.14.0+ Fix from $1,9502022-08-09 MEDIUM 5.5 CVE-2022-33715 Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of … Android Mitigation only Fix from $1,6002022-08-05 CRITICAL 9.8 CVE-2022-33719 Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow. Android Mitigation only Fix from $2,3002022-08-05