Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.4 CVE-2025-32073 Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediaw… Mitigation only Fix from $1,6002025-04-11 HIGH 7.8 CVE-2023-42977 A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to bre… Ipad Os 14.0 / 17.0+ Fix from $1,9502025-04-11 MEDIUM 5.4 CVE-2023-42981 Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed w… macOS Mitigation only Fix from $1,6002025-04-11 MEDIUM 6.5 CVE-2023-43037 IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. Maximo Application Suite 8.11.13+ Fix from $1,6002025-04-10 HIGH 7.4 CVE-2025-30648 An Improper Input Validation vulnerability in the Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenti… Junos 21.2+ Fix from $1,9502025-04-09 HIGH 7.5 CVE-2025-30649 An Improper Input Validation vulnerability in the syslog stream TCP transport of Juniper Networks Junos OS on MX240, MX480 and MX960 devices with MX-… Junos 22.2+ Fix from $1,9502025-04-09 MEDIUM 5.3 CVE-2025-31672 Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file forma… Poi 5.4.0+ Fix from $1,6002025-04-09 HIGH 7.8 CVE-2025-2223 CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstat… Mitigation only Fix from $1,9502025-04-09 MEDIUM 6.8 CVE-2025-30293 ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security f… Coldfusion Mitigation only Fix from $1,6002025-04-08 MEDIUM 6.8 CVE-2025-30294EPSS 16% ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security f… Coldfusion Mitigation only Fix from $1,6002025-04-08 CRITICAL 9.1 CVE-2025-24446 ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary co… Coldfusion Mitigation only Fix from $2,3002025-04-08 MEDIUM 5.5 CVE-2025-29821 Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. Dynamics 365 Business Central 2023 23.18.32409 / 24.12.32447+ Fix from $1,6002025-04-08 HIGH 7.8 CVE-2025-29811 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5189 / 10.0.22631.5189+ Fix from $1,9502025-04-08 HIGH 8.6 CVE-2025-27737 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-27731 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-27489 Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. Azure Stack Hci 22h2 10.0.20348.3328 / 10.0.25398.1486+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-26647 Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. Windows Server 2008 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24058 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24060 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24062 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.5737 / 10.0.19045.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24073 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24074 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-30151 Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-AP… Shopware 6.5.8.17 / 6.6.10.3+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-3413 A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this… Springboot Admin after 2017-12-26 Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2025-3250 A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of t… Eladmin Mitigation only Fix from $1,6002025-04-04 MEDIUM 5.3 CVE-2025-3165 A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of the file chitu/chitu/backend… Mitigation only Fix from $1,6002025-04-03 HIGH 7.8 CVE-2025-3162 A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file… Lmdeploy after 0.7.1 Fix from $1,9502025-04-03 CRITICAL 9.8 CVE-2025-31477 The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open progr… Plugin Shell 2.2.1+ Fix from $2,3002025-04-02 HIGH 7.5 CVE-2025-30080 Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of … Pexip Infinity 37.0+ Fix from $1,9502025-04-02 HIGH 7.5 CVE-2024-37917 Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted s… Pexip Infinity 35.0+ Fix from $1,9502025-04-02