Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2020-7839 In MaEPSBroker 2.5.0.31 and prior, a command injection vulnerability caused by improper input validation checks when parsing brokerCommand parameter. Maepsbroker after 2.5.0.31 Fix from $2,3002021-03-24 HIGH 7.5 CVE-2021-20222 A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat … Keycloak 13.0.0+ Fix from $1,9502021-03-23 HIGH 8.3 CVE-2021-21357 TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input valid… TYPO3 8.7.40 / 9.5.25+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21267 Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address va… Schema Inspector 2.0.0+ Fix from $1,9502021-03-19 HIGH 8.6 CVE-2020-25097EPSS 8% An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Req… Debian Linux 4.14 / 5.0.5+ Fix from $1,9502021-03-19 MEDIUM 6.5 CVE-2021-20631 Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App… Office after 10.8.4 Fix from $1,6002021-03-18 HIGH 7.8 CVE-2021-21085 Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vul… Connect after 11.0.7 Fix from $1,9502021-03-12 HIGH 7.8 CVE-2021-21069 Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an atta… Creative Cloud Desktop Application after 5.3 Fix from $1,9502021-03-12 MEDIUM 5.5 CVE-2021-0377 In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a loc… Android Mitigation only Fix from $1,6002021-03-10 HIGH 7.2 CVE-2021-20671 Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files … Growi Mitigation only Fix from $1,9502021-03-10 HIGH 7.8 CVE-2021-20268 An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls… Linux Kernel 5.10.10+ Fix from $1,9502021-03-09 HIGH 7.5 CVE-2021-20273 A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off. Debian Linux 3.0.32+ Fix from $1,9502021-03-09 MEDIUM 6.1 CVE-2021-21510 Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit th… Idrac8 Firmware 2.75.100.75+ Fix from $1,6002021-03-08 HIGH 8.8 CVE-2021-21506 PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenticated with ISI_PRIV_SYS_SUPPO… Emc Powerscale Onefs Mitigation only Fix from $1,9502021-03-08 HIGH 7.5 CVE-2021-26788 Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exp… Cyclonetcp after 2.0.0 Fix from $1,9502021-03-08 MEDIUM 6.1 CVE-2020-29029 Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascr… Gatemanager Firmware 9.4.62105402+ Fix from $1,6002021-03-05 MEDIUM 5.5 CVE-2021-25334 Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent d… Android Mitigation only Fix from $1,6002021-03-04 MEDIUM 5.2 CVE-2021-25338 Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to wr… Android Mitigation only Fix from $1,6002021-03-04 MEDIUM 5.2 CVE-2021-25339 Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corr… Android Mitigation only Fix from $1,6002021-03-04 HIGH 7.5 CVE-2021-23131 An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager. Joomla\! 3.9.25+ Fix from $1,9502021-03-04 CRITICAL 9.8 CVE-2021-21978EPSS 99% VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authoriza… View Planner 4.6+ Fix from $2,3002021-03-03 MEDIUM 6.5 CVE-2020-28591 An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 9… Fedora No fix yet Fix from $1,6002021-03-03 HIGH 7.5 CVE-2021-27921 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly… Pillow 8.1.1+ Fix from $1,9502021-03-03 HIGH 7.5 CVE-2021-27922 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly… Pillow 8.1.1+ Fix from $1,9502021-03-03 HIGH 7.5 CVE-2021-27923 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly… Pillow 8.1.1+ Fix from $1,9502021-03-03 CRITICAL 10.0 CVE-2021-21321 fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before ve… Fastify Reply From 4.0.2+ Fix from $2,3002021-03-02 CRITICAL 9.8 CVE-2021-21322 fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific … Fastify Http Proxy 4.3.1+ Fix from $2,3002021-03-02 MEDIUM 5.5 CVE-2021-1450 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attack… Anyconnect Secure Mobility Client Mitigation only Fix from $1,6002021-02-24 HIGH 8.2 CVE-2020-11987EPSS 14% Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-craf… Batik after 1.13 Fix from $1,9502021-02-24 HIGH 8.2 CVE-2020-11988EPSS 7% Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By usi… Xmlgraphics Commons after 2.4 Fix from $1,9502021-02-24