Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.1 CVE-2025-53471 Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are require… No fix yet Fix from $1,6002025-07-11 CRITICAL 9.3 CVE-2025-34102EPSS 7% A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and c… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.3 CVE-2025-34099 An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php compone… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.3 CVE-2025-34100 An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuer… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.3 CVE-2025-34101 An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoi… No fix yet Fix from $2,3002025-07-10 HIGH 7.5 CVE-2024-42516 HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hos… HTTP Server 2.4.64+ Fix from $1,9502025-07-10 HIGH 7.8 CVE-2025-6376 A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the b… Arena 16.20.09+ Fix from $1,9502025-07-09 HIGH 7.8 CVE-2025-6377 A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the b… Arena 16.20.09+ Fix from $1,9502025-07-09 HIGH 8.2 CVE-2025-53652 Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the… Git Parameter 444.vca_b_84d3703c2+ Fix from $1,9502025-07-09 MEDIUM 6.5 CVE-2025-44526 Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (B… Rtl8762e Software Development Kit No fix yet Fix from $1,6002025-07-09 MEDIUM 6.0 CVE-2025-7378 An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lea… Mitigation only Fix from $1,6002025-07-09 HIGH 7.3 CVE-2025-7216 A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /app… Mitigation only Fix from $1,9502025-07-09 HIGH 7.5 CVE-2025-49719EPSS 11% Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. Sql Server 2016 13.0.6460.7 / 13.0.7055.9+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47982 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-40593 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitr… Simatic Cn 4100 Firmware 4.0+ Fix from $1,6002025-07-08 HIGH 7.8 CVE-2025-24005 A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation. Charx Sec 3000 Firmware 1.7.3+ Fix from $1,9502025-07-08 MEDIUM 5.3 CVE-2025-24002 An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in … Charx Sec 3000 Firmware after 1.6.5 Fix from $1,6002025-07-08 HIGH 7.5 CVE-2025-26780 An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Servi… Exynos 2400 Firmware Mitigation only Fix from $1,9502025-07-07 MEDIUM 5.9 CVE-2025-7099 A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality … Boyuncms after 1.21 Fix from $1,6002025-07-07 HIGH 8.1 CVE-2025-7060 A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_in… Monitorr after 1.7.6m Fix from $1,9502025-07-04 MEDIUM 6.5 CVE-2025-53502 Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Scripting (XSS).This issue affe… Mitigation only Fix from $1,6002025-07-03 MEDIUM 6.5 CVE-2025-52891 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an… Patch available Fix from $1,6002025-07-02 CRITICAL 9.3 CVE-2025-34072 A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI… Mitigation only Fix from $2,3002025-07-02 MEDIUM 6.5 CVE-2025-27023 Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via cr… G42 Firmware 7.1+ Fix from $1,6002025-07-02 CRITICAL 9.4 CVE-2025-34055 An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the A… No fix yet Fix from $2,3002025-07-01 CRITICAL 9.4 CVE-2025-34056 An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group mana… No fix yet Fix from $2,3002025-07-01 CRITICAL 10.0 CVE-2025-34060 A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the … Mitigation only Fix from $2,3002025-07-01 CRITICAL 9.8 CVE-2025-53076 Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2. Rlottie Patch available Fix from $2,3002025-06-30 CRITICAL 9.8 CVE-2025-53075 Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2. Rlottie Patch available Fix from $2,3002025-06-30 HIGH 7.3 CVE-2025-5878 A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL … Patch available Fix from $1,9502025-06-29