Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.4 CVE-2024-5533 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sani… Divi 4.25.2+ Fix from $1,6002024-06-18 HIGH 7.5 CVE-2024-37794 Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file. Mitigation only Fix from $1,9502024-06-17 HIGH 7.8 CVE-2024-32903 In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local … Android Mitigation only Fix from $1,9502024-06-13 HIGH 7.8 CVE-2024-32907 In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege wi… Android Mitigation only Fix from $1,9502024-06-13 HIGH 8.2 CVE-2024-32859 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l… Xps 8960 Firmware 1.14.0 / 1.16.0+ Fix from $1,9502024-06-13 HIGH 8.2 CVE-2024-32860 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l… Alienware Area 51m R2 Firmware 1.0.24 / 1.1.12+ Fix from $1,9502024-06-13 HIGH 8.2 CVE-2024-32858 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l… Xps 8960 Firmware 1.14.0 / 1.16.0+ Fix from $1,9502024-06-13 MEDIUM 6.0 CVE-2024-32856 Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with l… Xps 8960 Firmware 1.14.0 / 1.16.0+ Fix from $1,6002024-06-13 HIGH 7.2 CVE-2024-34108 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result … Commerce after 1.4.0 Fix from $1,9502024-06-13 HIGH 7.2 CVE-2024-34109 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result … Commerce after 1.4.0 Fix from $1,9502024-06-13 HIGH 7.8 CVE-2024-30087EPSS 10% Win32k Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20680 / 10.0.14393.7070+ Fix from $1,9502024-06-11 HIGH 8.8 CVE-2024-30078EPSS 5% Windows Wi-Fi Driver Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20680 / 10.0.14393.7070+ Fix from $1,9502024-06-11 MEDIUM 6.2 CVE-2024-35212 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input valida… Sinec Traffic Analyzer 1.2+ Fix from $1,6002024-06-11 HIGH 7.5 CVE-2024-36471 Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp… Allura 1.17.0+ Fix from $1,9502024-06-10 MEDIUM 5.5 CVE-2024-27805 An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17… Ipados 10.5 / 12.7.5+ Fix from $1,6002024-06-10 HIGH 7.8 CVE-2024-31959 An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, whi… Exynos 2200 Firmware Mitigation only Fix from $1,9502024-06-07 HIGH 7.5 CVE-2024-36734 Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the … Oneflow Mitigation only Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-36740 An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size. Oneflow Mitigation only Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-36737 Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the … Oneflow Mitigation only Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-36745 An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.index_sel… Oneflow Mitigation only Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-36742 An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index parameter exc… Oneflow Mitigation only Fix from $1,9502024-06-06 CRITICAL 9.8 CVE-2024-5171 Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Ca… Libaom after 3.9.0 Fix from $2,3002024-06-05 HIGH 7.1 CVE-2024-27378 An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_acti… Exynos 980 Firmware Mitigation only Fix from $1,9502024-06-05 MEDIUM 6.1 CVE-2024-20405 A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack… Finesse 11.6+ Fix from $1,6002024-06-05 MEDIUM 5.4 CVE-2024-5439 The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.… Blocksy 2.0.51+ Fix from $1,6002024-06-05 HIGH 8.8 CVE-2024-23669 An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug… Fortiwebmanager 6.2.5 / 7.0.5+ Fix from $1,9502024-06-05 CRITICAL 9.8 CVE-2024-28103 Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o… Rails 6.1.7.8 / 7.0.8.4+ Fix from $2,3002024-06-04 HIGH 7.8 CVE-2022-1242 Apport can be tricked into connecting to arbitrary sockets as the root user Apport 2.21.0+ Fix from $1,9502024-06-03 HIGH 8.8 CVE-2024-23668 An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug… Fortiwebmanager 6.2.5 / 7.0.5+ Fix from $1,9502024-06-03 HIGH 7.5 CVE-2024-36390 MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service Devicehub Mitigation only Fix from $1,9502024-06-02