Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2025-40836 Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with es… Indoor Connect 8855 Firmware 2025.q2+ Fix from $2,3002025-09-25 MEDIUM 6.3 CVE-2025-10950 A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file m… Mitigation only Fix from $1,6002025-09-25 HIGH 8.8 CVE-2025-52907 Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.13… X6000r Firmware after 9.4.0cu.1360_b20241207 Fix from $1,9502025-09-24 HIGH 7.8 CVE-2025-47314 Memory corruption while processing data sent by FE driver. Qam8255p Firmware Mitigation only Fix from $1,9502025-09-24 HIGH 7.5 CVE-2025-52905EPSS 8% Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207. X6000r Firmware after 9.4.0cu.1360_b20241207 Fix from $1,9502025-09-23 HIGH 8.6 CVE-2025-59532 Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI co… Patch available Fix from $1,9502025-09-22 MEDIUM 6.5 CVE-2025-59535 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary them… Dotnetnuke 10.1.0+ Fix from $1,6002025-09-22 CRITICAL 9.8 CVE-2025-10771 A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnectio… Jimureport after 2.1.2 Fix from $2,3002025-09-21 MEDIUM 6.5 CVE-2025-10770 A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of… Jimureport after 2.1.2 Fix from $1,6002025-09-21 CRITICAL 9.8 CVE-2025-10768 A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB… H2o after 3.46.0.8 Fix from $2,3002025-09-21 CRITICAL 9.8 CVE-2025-10769 A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC… H2o after 3.46.0.8 Fix from $2,3002025-09-21 CRITICAL 9.1 CVE-2025-57644 Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe… Automation Platform Mitigation only Fix from $2,3002025-09-19 HIGH 7.7 CVE-2025-57528 An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1… Ac6 Firmware No fix yet Fix from $1,9502025-09-19 CRITICAL 9.8 CVE-2025-23268 NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may cause an improper input validation issue. A success… Triton Inference Server 25.07+ Fix from $2,3002025-09-17 HIGH 7.5 CVE-2025-23336 NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading a misconfi… Triton Inference Server 25.08+ Fix from $1,9502025-09-17 HIGH 7.8 CVE-2025-10155 An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacke… Picklescan 0.0.31+ Fix from $1,9502025-09-17 MEDIUM 5.5 CVE-2025-43375 The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. Xcode 26.0+ Fix from $1,6002025-09-15 HIGH 7.8 CVE-2025-43372 The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, vi… Ipados 26.0+ Fix from $1,9502025-09-15 CRITICAL 9.8 CVE-2025-43342 A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe… Safari 2.48.7 / 18.7+ Fix from $2,3002025-09-15 CRITICAL 9.8 CVE-2025-43347 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS … Ipados 26.0+ Fix from $2,3002025-09-15 MEDIUM 5.5 CVE-2025-43299 A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 1… Ipados 14.8 / 15.7+ Fix from $1,6002025-09-15 MEDIUM 5.5 CVE-2025-43293 The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be a… macOS 14.8 / 15.7+ Fix from $1,6002025-09-15 MEDIUM 6.3 CVE-2025-10433 A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the file /admin/api/workspace/def… Mitigation only Fix from $1,6002025-09-15 MEDIUM 5.3 CVE-2024-45431EPSS 5% OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue … Blue Sdk after 6.0.1 Fix from $1,6002025-09-12 MEDIUM 6.5 CVE-2025-58364 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deseri… Cups 2.4.13+ Fix from $1,6002025-09-11 CRITICAL 9.8 CVE-2025-54123EPSS 11% Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injec… Hoverfly 1.12.0+ Fix from $2,3002025-09-10 HIGH 7.5 CVE-2025-56404 An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user valid… Model Context Protocol No fix yet Fix from $1,9502025-09-10 MEDIUM 6.5 CVE-2025-58759 TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .… Tinyenv 1.0.11+ Fix from $1,6002025-09-09 HIGH 7.3 CVE-2025-10164 A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tenso… Mitigation only Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-54247 Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security fea… Experience Manager after 2025.8.0 Fix from $1,6002025-09-09