Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2025-12687 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows m… Digital Employee Experience 25.11+ Fix from $1,6002025-12-11 MEDIUM 6.2 CVE-2025-61822 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file… Coldfusion Mitigation only Fix from $1,6002025-12-10 CRITICAL 9.1 CVE-2025-61809 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security f… Coldfusion Mitigation only Fix from $2,3002025-12-10 HIGH 8.4 CVE-2025-61812 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privilege… Coldfusion Mitigation only Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-64666 Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Exchange Server 15.02.2562.035+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62571 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62455 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.2 CVE-2025-12945 A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. T… R7000p Firmware after 1.3.3.154 Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-12946 A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the route… Rs700 Firmware 1.0.9.6 / 1.0.17.142+ Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2025-40831 A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date param… Sinec Security Monitor 4.10.0+ Fix from $1,6002025-12-09 HIGH 8.4 CVE-2025-2296 EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulne… Mitigation only Fix from $1,9502025-12-09 HIGH 7.2 CVE-2025-13428 A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote … Security Operations Soar 6.3.64+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-48632 In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due … Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48638 In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of p… Android Mitigation only Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48623 In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of pri… Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48624 In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation… Android Mitigation only Fix from $1,9502025-12-08 MEDIUM 5.5 CVE-2025-48601 In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privi… Android Mitigation only Fix from $1,6002025-12-08 HIGH 7.8 CVE-2025-48612 In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to… Android Mitigation only Fix from $1,9502025-12-08 HIGH 7.3 CVE-2025-48594 In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to im… Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48525 In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a compan… Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48566 In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead … Android Patch available Fix from $1,9502025-12-08 MEDIUM 6.7 CVE-2025-22432 In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to loc… Android Patch available Fix from $1,6002025-12-08 HIGH 7.5 CVE-2025-26488 Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the applian… Infinera Mtc 9 Firmware 23.0+ Fix from $1,9502025-12-08 MEDIUM 6.5 CVE-2025-26489 Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, … Infinera Mtc 9 Firmware 23.0+ Fix from $1,6002025-12-08 HIGH 7.2 CVE-2025-54306 An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network con… Torrent Suite Software Mitigation only Fix from $1,9502025-12-04 HIGH 7.5 CVE-2024-3884 A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSource… Mitigation only Fix from $1,9502025-12-03 MEDIUM 6.5 CVE-2025-20389 In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app o… Splunk 3.7.28 / 3.8.58+ Fix from $1,6002025-12-03 MEDIUM 5.3 CVE-2025-66400 mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdow… Mdast Util To Hast 13.2.1+ Fix from $1,6002025-12-01 MEDIUM 6.5 CVE-2025-63095 Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of S… Hello Video Codec Patch available Fix from $1,6002025-12-01 HIGH 7.5 CVE-2025-26858 A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted set of network packe… Diris M 70 Firmware Mitigation only Fix from $1,9502025-12-01