Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2024-39780 A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting… Robot Operating System Patch available Fix from $2,3002025-04-02 HIGH 8.8 CVE-2025-3068 Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation … Chrome 135.0.7049.52+ Fix from $1,9502025-04-02 MEDIUM 6.5 CVE-2025-3070 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escal… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 MEDIUM 5.3 CVE-2025-31135 Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY command will be accepted mult… Patch available Fix from $1,6002025-04-01 HIGH 8.1 CVE-2025-31132 Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fix… Mitigation only Fix from $1,9502025-04-01 HIGH 7.5 CVE-2025-30471 A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonom… Ipados 2.4 / 13.7.5+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-30452 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An input validati… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 HIGH 8.4 CVE-2025-24255 A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.… macOS 13.7.5 / 14.7.5+ Fix from $1,9502025-03-31 MEDIUM 5.5 CVE-2025-24191 The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify pr… macOS 15.4+ Fix from $1,6002025-03-31 HIGH 7.5 CVE-2023-0881 Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subseq… Linux Bluefield 5.4.0-1058.64+ Fix from $1,9502025-03-31 MEDIUM 5.3 CVE-2025-1734 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server… PHP 8.1.32 / 8.2.28+ Fix from $1,6002025-03-30 HIGH 7.3 CVE-2025-1736 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, th… PHP 8.1.32 / 8.2.28+ Fix from $1,9502025-03-30 HIGH 7.2 CVE-2025-2855 A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of… Eladmin after 2.7 Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30355 Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1… Synapse 1.127.1+ Fix from $1,9502025-03-27 MEDIUM 5.3 CVE-2025-1440 The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all ve… Advanced Iframe 2025.0+ Fix from $1,6002025-03-26 HIGH 7.3 CVE-2025-1514 The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unauthorized filter calling due to… Mitigation only Fix from $1,9502025-03-26 HIGH 8.8 CVE-2025-30213 Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a spec… Frappe 14.91.0 / 15.52.0+ Fix from $1,9502025-03-25 HIGH 8.8 CVE-2025-24514EPSS 33% A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to… No fix yet Fix from $1,9502025-03-25 HIGH 8.8 CVE-2025-1098EPSS 83% A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress an… No fix yet Fix from $1,9502025-03-25 HIGH 8.8 CVE-2025-1097EPSS 36% A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can b… No fix yet Fix from $1,9502025-03-25 CRITICAL 9.8 CVE-2025-2690 A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src… Yii after 2.0.39 Fix from $2,3002025-03-24 CRITICAL 9.8 CVE-2025-2689 A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of… Yii after 2.0.45 Fix from $2,3002025-03-24 HIGH 8.8 CVE-2025-2622 A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/w… Snail Job No fix yet Fix from $1,9502025-03-22 MEDIUM 5.3 CVE-2024-13666 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing … Mitigation only Fix from $1,6002025-03-22 HIGH 8.8 CVE-2025-29814 Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $1,9502025-03-21 HIGH 7.5 CVE-2025-1385 When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamica… Mitigation only Fix from $1,9502025-03-20 HIGH 7.3 CVE-2025-2376 A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCo… Mitigation only Fix from $1,9502025-03-17 MEDIUM 6.5 CVE-2025-1767 This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Sin… Patch available Fix from $1,6002025-03-13 MEDIUM 5.9 CVE-2024-9042 This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below. No fix yet Fix from $1,6002025-03-13 HIGH 8.7 CVE-2024-26290 Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid … Mitigation only Fix from $1,9502025-03-12