Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2022-26889 In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an … Splunk 8.1.2+ Fix from $1,9502022-05-06 HIGH 8.1 CVE-2021-25745 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi… Ingress Nginx 1.2.0+ Fix from $1,9502022-05-06 HIGH 7.1 CVE-2021-25746 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress o… Ingress Nginx 1.2.0+ Fix from $1,9502022-05-06 MEDIUM 5.3 CVE-2022-29479 On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11… Big Ip Access Policy Manager Mitigation only Fix from $1,6002022-05-05 HIGH 7.2 CVE-2022-28695 On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior t… Big Ip Advanced Firewall Manager Mitigation only Fix from $1,9502022-05-05 MEDIUM 5.9 CVE-2022-28708 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, when a BIG-IP DNS resolver-enabled, HTTP-Explicit or SOCKS prof… Big Ip Access Policy Manager Mitigation only Fix from $1,6002022-05-05 HIGH 7.2 CVE-2022-27634 On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authent… Big Ip Access Policy Manager 15.1.5.1 / 16.1.2.2+ Fix from $1,9502022-05-05 HIGH 7.5 CVE-2022-22433 IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied… Robotic Process Automation 21.0.1.5+ Fix from $1,9502022-05-05 HIGH 8.8 CVE-2022-20779EPSS 10% Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM… Enterprise Nfv Infrastructure Software 4.7.1+ Fix from $1,9502022-05-04 MEDIUM 6.7 CVE-2022-28781 Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch … Android Mitigation only Fix from $1,6002022-05-03 HIGH 7.1 CVE-2022-28783 Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages withou… Android Mitigation only Fix from $1,9502022-05-03 MEDIUM 5.5 CVE-2022-28791 Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a spec… Galaxy Store 4.5.41.8+ Fix from $1,6002022-05-03 HIGH 8.6 CVE-2022-20715 A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So… Secure Firewall Threat Defense 6.4.0.15 / 6.6.5.2+ Fix from $1,9502022-05-03 HIGH 7.5 CVE-2022-20745 A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower … Secure Firewall Threat Defense 6.4.0.15 / 6.6.5.2+ Fix from $1,9502022-05-03 HIGH 7.5 CVE-2022-21144 This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invok… Libxmljs 0.19.8+ Fix from $1,9502022-05-01 CRITICAL 9.1 CVE-2021-41945 Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. Httpx 0.23.0+ Fix from $2,3002022-04-28 MEDIUM 5.7 CVE-2022-28195 NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may… Jetson Linux 32.7.2+ Fix from $1,6002022-04-27 MEDIUM 5.6 CVE-2022-28193 NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may al… Jetson Linux 32.7.2+ Fix from $1,6002022-04-27 CRITICAL 9.8 CVE-2022-24881 Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote… Codegen 1.0.0+ Fix from $2,3002022-04-26 CRITICAL 9.8 CVE-2022-29499 KEVEPSS 55% The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Serv… Mivoice Connect after 22.20.2300.0 Fix from $2,3002022-04-26 MEDIUM 6.7 CVE-2021-4211 A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models… A340 22icb Firmware Mitigation only Fix from $1,6002022-04-22 MEDIUM 6.7 CVE-2021-4212 A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with … C340 14iml Firmware Patch available Fix from $1,6002022-04-22 MEDIUM 6.7 CVE-2022-1107 During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some… Thinkpad 11e Firmware Mitigation only Fix from $1,6002022-04-22 MEDIUM 6.7 CVE-2022-1108 A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploite… Thinkpad X1 Fold Gen 1 Firmware Mitigation only Fix from $1,6002022-04-22 MEDIUM 6.7 CVE-2021-3970 A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with… Ideapad 3 14ada05 Firmware Mitigation only Fix from $1,6002022-04-22 MEDIUM 6.7 CVE-2021-4210 A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow a… Stadia Ggp 120 Firmware Patch available Fix from $1,6002022-04-22 HIGH 7.5 CVE-2022-24423 Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this … Integrated Dell Remote Access Controller 8 Firmware 2.83.83.83+ Fix from $1,9502022-04-21 HIGH 7.5 CVE-2022-20783 A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could all… Telepresence Collaboration Endpoint 9.15.10.8 / 10.11.2.2+ Fix from $1,9502022-04-21 HIGH 8.8 CVE-2022-24861 Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC dri… Databasir Patch available Fix from $1,9502022-04-20 CRITICAL 9.1 CVE-2022-0567 A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses e… Ovn Kubernetes 4.7.47 / 4.8.36+ Fix from $2,3002022-04-20