Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.1 CVE-2025-40846 Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users t… Mitigation only Fix from $1,9502025-05-08 HIGH 8.2 CVE-2025-20197 A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to roo… Ios Xe Mitigation only Fix from $1,9502025-05-07 HIGH 8.6 CVE-2025-20154 A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unau… iOS after 17.2.3 Fix from $1,9502025-05-07 HIGH 7.8 CVE-2025-21460 Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously. Qam8255p Firmware Mitigation only Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-49844 Memory corruption while triggering commands in the PlayReady Trusted application. Ar8035 Firmware Mitigation only Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-49845 Memory corruption during the FRS UDS generation process. Wcd9385 Firmware No fix yet Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-45577 Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information. Fastconnect 6900 Firmware Patch available Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-45579 Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory… Fastconnect 6900 Firmware Patch available Fix from $1,9502025-05-06 MEDIUM 5.4 CVE-2025-46340 Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the vali… Misskey 2025.4.1+ Fix from $1,6002025-05-05 HIGH 8.3 CVE-2025-4260 A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the … Youkefu No fix yet Fix from $1,9502025-05-05 HIGH 7.8 CVE-2024-13943 Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to… Model S Firmware 2024.8+ Fix from $1,9502025-04-30 HIGH 7.5 CVE-2025-30391 Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. Dynamics 365 Customer Service Mitigation only Fix from $1,9502025-04-30 HIGH 7.3 CVE-2025-22235 EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not expos… Mitigation only Fix from $1,9502025-04-28 MEDIUM 5.3 CVE-2025-46574 There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensit… Zxcloud Goldendb 6.1.03.11+ Fix from $1,6002025-04-27 HIGH 7.5 CVE-2025-26413 Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it … Kvrocks 2.12.0+ Fix from $1,9502025-04-22 MEDIUM 6.1 CVE-2025-3837 An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purp… Mitigation only Fix from $1,6002025-04-21 HIGH 7.5 CVE-2025-29784 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for … Nameless 2.2.0+ Fix from $1,9502025-04-18 MEDIUM 6.5 CVE-2025-27599 Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally install… Patch available Fix from $1,6002025-04-18 HIGH 8.8 CVE-2025-26477 Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially… Elastic Cloud Storage 4.0.0.0+ Fix from $1,9502025-04-17 MEDIUM 5.3 CVE-2025-3677 A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low… Mitigation only Fix from $1,6002025-04-16 MEDIUM 5.5 CVE-2025-3622 A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file … Mitigation only Fix from $1,6002025-04-15 MEDIUM 6.3 CVE-2025-3590 A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability is an unknown functionality.… Mitigation only Fix from $1,6002025-04-14 MEDIUM 6.9 CVE-2025-32075 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Tabs Extension allows Code Injection.This issue affects Mediawiki - T… Mitigation only Fix from $1,6002025-04-11 MEDIUM 6.9 CVE-2025-32076 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Visual Data Extension allows HTTP DoS.This issue affects Mediawiki - … Mitigation only Fix from $1,6002025-04-11 MEDIUM 6.9 CVE-2025-32077 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Extension:SimpleCalendar allows Cross-Site Scripting (XSS).This issue… Mitigation only Fix from $1,6002025-04-11 MEDIUM 6.5 CVE-2025-32079 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments allows HTTP DoS.This issue affects Mediawiki - Grow… Mitigation only Fix from $1,6002025-04-11 MEDIUM 5.4 CVE-2025-32067 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Growth Experiments Extension allows Cross-Site Scripting (XSS).This i… Mitigation only Fix from $1,6002025-04-11 MEDIUM 5.4 CVE-2025-32069 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This … Mitigation only Fix from $1,6002025-04-11 MEDIUM 5.4 CVE-2025-32070 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - AJAX Poll Extension allows Cross-Site Scripting (XSS).This issue affe… Mitigation only Fix from $1,6002025-04-11 MEDIUM 5.4 CVE-2025-32071 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight… Mitigation only Fix from $1,6002025-04-11