Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.7 CVE-2025-54248EPSS 5% Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security fea… Experience Manager after 2025.8.0 Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-53809 Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. Windows 11 24h2 10.0.26100.6508+ Fix from $1,6002025-09-09 CRITICAL 9.1 CVE-2025-54236 KEVEPSS 95% Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vu… Commerce Mitigation only Fix from $2,3002025-09-09 MEDIUM 6.5 CVE-2025-8007 A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trig… 1756 En2tr Series A Firmware 7.001+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-10061 An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect h… MongoDB 6.0.25 / 7.0.22+ Fix from $1,6002025-09-05 HIGH 8.2 CVE-2025-58353 Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio… Mitigation only Fix from $1,9502025-09-04 CRITICAL 9.3 CVE-2025-58361 Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive U… Mitigation only Fix from $2,3002025-09-04 HIGH 7.8 CVE-2025-32322 In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recordi… Android Mitigation only Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-48559 In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to l… Android Patch available Fix from $1,6002025-09-04 HIGH 7.3 CVE-2025-48556 In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. This could … Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-48538 In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input v… Android Patch available Fix from $1,6002025-09-04 HIGH 7.8 CVE-2025-48541 In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This coul… Android Patch available Fix from $1,9502025-09-04 HIGH 7.1 CVE-2025-48537 In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information … Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-32323 In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-26429 In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial… Android Patch available Fix from $1,6002025-09-04 MEDIUM 5.1 CVE-2025-26426 In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due t… Android Mitigation only Fix from $1,6002025-09-04 MEDIUM 5.3 CVE-2025-9467 When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Use… Mitigation only Fix from $1,6002025-09-04 HIGH 7.8 CVE-2024-56190 In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escal… Android Mitigation only Fix from $1,9502025-09-04 HIGH 8.8 CVE-2024-43115 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This… Dolphinscheduler 3.2.2+ Fix from $1,9502025-09-03 MEDIUM 6.8 CVE-2023-21472 Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in … Android Mitigation only Fix from $1,6002025-09-03 MEDIUM 6.8 CVE-2023-21473 Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in … Android Mitigation only Fix from $1,6002025-09-03 MEDIUM 6.5 CVE-2025-46047 A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin… Silverpeas Patch available Fix from $1,6002025-09-02 HIGH 7.5 CVE-2025-52547 E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to con… E3 Supervisory Controller Firmware 2.31f01+ Fix from $1,9502025-09-02 HIGH 7.5 CVE-2025-52544 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan fil… E3 Supervisory Controller Firmware 2.31f01+ Fix from $1,9502025-09-02 MEDIUM 5.3 CVE-2025-57220 An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP p… Ac10 Firmware Mitigation only Fix from $1,6002025-08-28 HIGH 8.8 CVE-2024-37777 O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function. O2oa No fix yet Fix from $1,9502025-08-27 HIGH 8.8 CVE-2025-34159 Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platf… Coolify 4.0.0+ Fix from $1,9502025-08-27 HIGH 8.8 CVE-2025-34161 Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform … Coolify 4.0.0+ Fix from $1,9502025-08-27 CRITICAL 9.0 CVE-2025-34157 Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authent… Coolify 4.0.0+ Fix from $2,3002025-08-27 HIGH 7.5 CVE-2025-57810 jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilizati… Jspdf 3.0.2+ Fix from $1,9502025-08-26