Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.3 CVE-2025-4742 A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to 9024b43f091e2eb9bac65802b120c0b35f9ba856. Affected is the functi… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-4740 A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affects unknown code of the file co… Mitigation only Fix from $1,6002025-05-16 HIGH 7.9 CVE-2024-52880 An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.5… Kernel 5.29.50 / 5.38.50+ Fix from $1,9502025-05-15 MEDIUM 5.3 CVE-2025-4701 A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.l… Mitigation only Fix from $1,6002025-05-15 MEDIUM 6.6 CVE-2025-46836 net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to … Patch available Fix from $1,6002025-05-14 MEDIUM 5.9 CVE-2025-47888 Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured Ding… Dingtalk after 2.7.3 Fix from $1,6002025-05-14 CRITICAL 9.6 CVE-2025-47777 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stor… 5ire 0.11.1+ Fix from $2,3002025-05-14 CRITICAL 9.1 CVE-2025-43559 ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary co… Coldfusion Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.1 CVE-2025-43560EPSS 19% ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary co… Coldfusion Mitigation only Fix from $2,3002025-05-13 HIGH 7.5 CVE-2025-24308 Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially ena… Mitigation only Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-21094 Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially… Mitigation only Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-20031 Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access. Mitigation only Fix from $1,6002025-05-13 HIGH 7.9 CVE-2025-20032 Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentiall… Proset\/wireless Wifi 23.100.0+ Fix from $1,9502025-05-13 MEDIUM 5.3 CVE-2025-20034 Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before version R0… Mitigation only Fix from $1,6002025-05-13 HIGH 7.8 CVE-2025-32706 KEV Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-29968 Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. Windows Server 2008 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,6002025-05-13 MEDIUM 5.5 CVE-2025-29955 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. Windows 11 24h2 10.0.25398.1611 / 10.0.26100.4061+ Fix from $1,6002025-05-13 MEDIUM 6.5 CVE-2025-40556 A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versions), BA… Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.5 CVE-2025-24510 A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle specific incoming BACnet MSTP mes… Mitigation only Fix from $1,6002025-05-13 HIGH 7.8 CVE-2025-31259 A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.… macOS 15.5+ Fix from $1,9502025-05-12 HIGH 7.5 CVE-2025-31240 This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a malic… macOS 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 MEDIUM 6.3 CVE-2025-31233 The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS S… Ipados 2.5 / 11.5+ Fix from $1,6002025-05-12 MEDIUM 6.5 CVE-2025-31215 The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 1… Safari 2.5 / 11.5+ Fix from $1,6002025-05-12 MEDIUM 6.5 CVE-2025-31217 The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15… Safari 2.5 / 11.5+ Fix from $1,6002025-05-12 HIGH 7.8 CVE-2025-30442 The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An ap… macOS 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 HIGH 7.5 CVE-2025-31208 The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6… Ipados 2.5 / 11.5+ Fix from $1,9502025-05-12 HIGH 7.8 CVE-2025-24274 An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventur… macOS 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 CRITICAL 9.3 CVE-2025-1087 Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vuln… Mitigation only Fix from $2,3002025-05-09 HIGH 8.3 CVE-2025-4377 Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.… Mitigation only Fix from $1,9502025-05-09 MEDIUM 5.3 CVE-2025-4376 Improper Input Validation vulnerability in Sparx Systems Pro Cloud Server's WebEA model search field allows Cross-Site Scripting (XSS). This issue a… Mitigation only Fix from $1,6002025-05-09