Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.1 CVE-2025-59250 Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. Jdbc Driver For Sql Server 10.2.4 / 11.2.4+ Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-59248 Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Exchange Server 15.02.2562.029+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-59228 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20262+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59207 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 MEDIUM 5.0 CVE-2025-59198 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-59187 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59190 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-58716 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-55692 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 8.7 CVE-2025-9066 A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused… Mitigation only Fix from $1,9502025-10-14 HIGH 7.5 CVE-2011-20001 A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (… Mitigation only Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-62162 cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malform… Mitigation only Fix from $1,9502025-10-10 HIGH 7.5 CVE-2025-61920 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JW… Authlib 1.6.5+ Fix from $1,9502025-10-10 MEDIUM 6.5 CVE-2025-27040 Information disclosure may occur while processing the hypervisor log. Csr8811 Firmware No fix yet Fix from $1,6002025-10-09 MEDIUM 5.1 CVE-2025-61768 KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists i… Patch available Fix from $1,6002025-10-06 CRITICAL 9.8 CVE-2025-11346 A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such ma… Ilias Mitigation only Fix from $2,3002025-10-06 CRITICAL 9.8 CVE-2025-11345 A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulati… Ilias Mitigation only Fix from $2,3002025-10-06 MEDIUM 6.3 CVE-2025-11273 A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oa… Mitigation only Fix from $1,6002025-10-04 HIGH 7.2 CVE-2025-60787EPSS 18% MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is w… Motioneye No fix yet Fix from $1,9502025-10-03 HIGH 7.1 CVE-2025-34226 OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is … Patch available Fix from $1,9502025-10-03 HIGH 7.5 CVE-2025-61582 TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and e… Ts3 Manager 2.2.2+ Fix from $1,9502025-10-01 MEDIUM 6.1 CVE-2025-61583 TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in version… Ts3 Manager 2.2.2+ Fix from $1,6002025-10-01 HIGH 7.5 CVE-2025-59537 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through … Argo Cd 2.14.20 / 3.0.19+ Fix from $1,9502025-10-01 HIGH 7.0 CVE-2025-11226 ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allow… Mitigation only Fix from $1,9502025-10-01 HIGH 8.7 CVE-2025-59952 MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service… Patch available Fix from $1,9502025-09-30 MEDIUM 6.5 CVE-2025-59940 mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input c… Patch available Fix from $1,6002025-09-29 HIGH 7.3 CVE-2025-11135 A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the func… Mitigation only Fix from $1,9502025-09-29 MEDIUM 6.3 CVE-2025-10975 A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.rob… Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.3 CVE-2025-10974 A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of th… Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.3 CVE-2025-10965 A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/co… Mitigation only Fix from $1,6002025-09-25