Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.7 CVE-2025-57805 The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article… Mitigation only Fix from $1,9502025-08-25 MEDIUM 6.7 CVE-2025-55301 The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local storage to edit the account's us… Mitigation only Fix from $1,6002025-08-25 HIGH 8.5 CVE-2025-52451 Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) all… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-08-22 HIGH 7.8 CVE-2025-50674 An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local au… Openmediavault No fix yet Fix from $1,9502025-08-22 CRITICAL 9.1 CVE-2025-9287 Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4. Cipher Base after 1.0.4 Fix from $2,3002025-08-20 CRITICAL 9.1 CVE-2025-9288 Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11. Sha.js after 2.4.11 Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-55444 A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote at… Online Artwork And Fine Arts Project Mitigation only Fix from $2,3002025-08-20 HIGH 8.7 CVE-2011-10020 Kaillera Server version 0.86 is vulnerable to a denial-of-service condition triggered by sending a malformed UDP packet after the initial handshake. … No fix yet Fix from $1,9502025-08-20 HIGH 7.5 CVE-2025-36114 IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall… Soar Qradar Plugin App after 5.6.0 Fix from $1,9502025-08-20 CRITICAL 9.3 CVE-2025-7693 A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED s… Mitigation only Fix from $2,3002025-08-18 HIGH 7.5 CVE-2025-6625 CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device. Mitigation only Fix from $1,9502025-08-18 MEDIUM 5.4 CVE-2025-52620 HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately valida… Bigfix Saas 8.1.14+ Fix from $1,6002025-08-15 CRITICAL 9.1 CVE-2025-9060 A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the in… Mitigation only Fix from $2,3002025-08-15 MEDIUM 6.4 CVE-2025-7507 The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and including, 1.1.0. This is due to the pl… Mitigation only Fix from $1,6002025-08-15 HIGH 8.5 CVE-2025-20148 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote … Secure Firewall Management Center Mitigation only Fix from $1,9502025-08-14 HIGH 8.8 CVE-2025-8876 KEV Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. N Central 2025.3.1+ Fix from $1,9502025-08-14 HIGH 7.3 CVE-2025-7971 A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file,… No fix yet Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-8963 A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDat… Jimureport after 2.1.1 Fix from $2,3002025-08-14 HIGH 8.3 CVE-2025-27388 Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens. Mitigation only Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-4410 A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by execute… No fix yet Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-4277 Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level. Mitigation only Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-4276 UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level. Mitigation only Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-49554 Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vu… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502025-08-12 MEDIUM 6.5 CVE-2025-25005 Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. Exchange Server 15.02.2562.020+ Fix from $1,6002025-08-12 MEDIUM 5.5 CVE-2025-27537 Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated … Mitigation only Fix from $1,6002025-08-12 HIGH 7.8 CVE-2025-24484 Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user… Mitigation only Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-24486 Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user… Mitigation only Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-24325 Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user… Mitigation only Fix from $1,9502025-08-12 MEDIUM 6.0 CVE-2025-24296 Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial of service … Mitigation only Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-21086 Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user… Mitigation only Fix from $1,9502025-08-12