Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2024-44809 A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sani… Mitigation only Fix from $2,3002024-09-03 HIGH 7.8 CVE-2024-38811 VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with… Fusion 13.6+ Fix from $1,9502024-09-03 HIGH 7.1 CVE-2024-23362 Cryptographic issue while parsing RSA keys in COBR format. 9205 Lte Modem Firmware Mitigation only Fix from $1,9502024-09-02 MEDIUM 6.0 CVE-2024-38303 Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker w… Emc Xc Core Xcxr2 Firmware 2.22.1 / 2.22.2+ Fix from $1,6002024-08-29 HIGH 8.1 CVE-2024-45058 i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to… I Educar after 2.9 Fix from $1,9502024-08-28 MEDIUM 5.3 CVE-2024-41565 JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specif… Justenoughitems 11.6.0.1021 / 13.1.0.18+ Fix from $1,6002024-08-28 HIGH 8.2 CVE-2021-38122 A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information… Netiq Advanced Authentication 6.3+ Fix from $1,9502024-08-28 CRITICAL 9.8 CVE-2024-7988 A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code… Thinmanager Thinserver 11.1.8 / 11.2.9+ Fix from $2,3002024-08-26 CRITICAL 9.8 CVE-2024-8073 Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issu… Web Application Firewall Mitigation only Fix from $2,3002024-08-26 CRITICAL 9.8 CVE-2024-45258 The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses… Patch available Fix from $2,3002024-08-25 HIGH 7.5 CVE-2024-45236 An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a… Fort Validator 1.6.3+ Fix from $1,9502024-08-24 CRITICAL 9.8 CVE-2024-42531 Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a s… Mitigation only Fix from $2,3002024-08-23 CRITICAL 9.8 CVE-2024-45169 An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper r… Idol2 after 2.12 Fix from $2,3002024-08-22 CRITICAL 9.8 CVE-2024-45167 An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper r… Idol2 after 2.12 Fix from $2,3002024-08-22 HIGH 8.8 CVE-2024-7974 Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a… Chrome 128.0.6613.84+ Fix from $1,9502024-08-21 HIGH 7.8 CVE-2024-7977 Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation… Chrome 128.0.6613.84+ Fix from $1,9502024-08-21 HIGH 7.8 CVE-2024-7980 Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation… Chrome 128.0.6613.84+ Fix from $1,9502024-08-21 HIGH 7.8 CVE-2024-33657 This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak informatio… Aptio V after 5.36 Fix from $1,9502024-08-21 MEDIUM 6.1 CVE-2020-11850 Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Pa… Netiq Self Service Password Reset 4.4+ Fix from $1,6002024-08-21 MEDIUM 6.5 CVE-2024-25009 Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can l… Mitigation only Fix from $1,6002024-08-20 HIGH 8.8 CVE-2024-7646EPSS 27% A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions`… Patch available Fix from $1,9502024-08-16 MEDIUM 6.8 CVE-2024-25008 Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary co… Mitigation only Fix from $1,6002024-08-16 HIGH 7.8 CVE-2024-43373 webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifical… Webcrack 2.14.1+ Fix from $1,9502024-08-15 HIGH 7.5 CVE-2024-7515 CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecov… Compactlogix 5380 Firmware 34.014+ Fix from $1,9502024-08-14 MEDIUM 6.5 CVE-2024-7507 CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is … Compactlogix 5380 Firmware 34.014+ Fix from $1,6002024-08-14 HIGH 7.8 CVE-2024-41856 Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary… Illustrator 27.9.5 / 28.6+ Fix from $1,9502024-08-14 MEDIUM 5.5 CVE-2024-34118 Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-… Illustrator 27.9.5 / 28.6+ Fix from $1,6002024-08-14 HIGH 8.2 CVE-2024-28947 Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileg… Server Board S2600st Firmware 02.01.0017+ Fix from $1,9502024-08-14 HIGH 8.2 CVE-2024-34163 Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access. Nuc X15 Laptop Kit Lapbc510 Firmware 0048 / 0065+ Fix from $1,9502024-08-14 HIGH 8.8 CVE-2024-21810 Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow a… Mitigation only Fix from $1,9502024-08-14