Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2023-28911 A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied dat… Mitigation only Fix from $1,6002025-06-28 HIGH 8.7 CVE-2025-34047 A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files o… Mitigation only Fix from $1,9502025-06-26 CRITICAL 10.0 CVE-2025-34043EPSS 8% A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.c… Mitigation only Fix from $2,3002025-06-26 HIGH 7.5 CVE-2025-6709 The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC… MongoDB 6.0.21 / 7.0.17+ Fix from $1,9502025-06-26 MEDIUM 6.5 CVE-2025-6703 Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2. Neqo after 0.13.2 Fix from $1,6002025-06-26 MEDIUM 5.9 CVE-2025-6444 ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attackers to relay NTLM credential… Servicestack 8.6+ Fix from $1,6002025-06-25 HIGH 7.5 CVE-2025-52894 OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao befo… Openbao 2.3.0+ Fix from $1,9502025-06-25 MEDIUM 6.6 CVE-2025-52569 GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-prov… Patch available Fix from $1,6002025-06-25 MEDIUM 6.6 CVE-2025-50178 GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certa… Patch available Fix from $1,6002025-06-25 HIGH 8.8 CVE-2025-52568 NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory cor… Patch available Fix from $1,9502025-06-24 CRITICAL 9.1 CVE-2025-6545 Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program fil… Patch available Fix from $2,3002025-06-23 CRITICAL 9.1 CVE-2025-6547 Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2. Patch available Fix from $2,3002025-06-23 HIGH 7.8 CVE-2025-34021 A server-side request forgery (SSRF) vulnerability exists in multiple Selea Targa IP OCR-ANPR camera models, including iZero, Targa 512, Targa 504, T… No fix yet Fix from $1,9502025-06-20 HIGH 8.0 CVE-2025-6279 A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the f… Upsonic after 0.55.6 Fix from $1,9502025-06-19 HIGH 7.1 CVE-2025-29646 An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest pac… Open5gs after 2.7.2 Fix from $1,9502025-06-18 MEDIUM 6.7 CVE-2024-55567 Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and … Insydeh2o 5.4.05.47.01 / 5.5.05.55.01+ Fix from $1,6002025-06-12 HIGH 8.8 CVE-2025-4613 Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b… Web Designer 16.3.0.0407+ Fix from $1,9502025-06-12 CRITICAL 9.5 CVE-2024-1244 Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in p… Mitigation only Fix from $2,3002025-06-11 HIGH 7.2 CVE-2024-1243 Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to… Wazuh 4.8.0+ Fix from $1,9502025-06-11 HIGH 8.7 CVE-2025-0051 Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service. Mitigation only Fix from $1,9502025-06-10 HIGH 8.3 CVE-2025-0052 Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service. Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47968 Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. Autoupdate 4.79+ Fix from $1,9502025-06-10 MEDIUM 6.7 CVE-2025-47171 Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,6002025-06-10 MEDIUM 6.5 CVE-2025-3898 CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request co… Mitigation only Fix from $1,6002025-06-10 HIGH 8.6 CVE-2025-4680 Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Contr… Mitigation only Fix from $1,9502025-06-10 MEDIUM 6.5 CVE-2025-3116 CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malforme… No fix yet Fix from $1,6002025-06-10 CRITICAL 9.8 CVE-2025-1041 An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web re… Call Management System 19.2.0.7 / 20.0.1.0+ Fix from $2,3002025-06-10 MEDIUM 6.6 CVE-2025-0037 In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to i… No fix yet Fix from $1,6002025-06-10 MEDIUM 5.5 CVE-2025-27131 in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. Openharmony after 5.0.3 Fix from $1,6002025-06-08 MEDIUM 5.5 CVE-2025-27242 in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. Openharmony after 5.0.3 Fix from $1,6002025-06-08