Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2024-3488 File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a f… Imanager 3.2.6+ Fix from $2,3002024-05-15 CRITICAL 9.8 CVE-2024-3968 Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upl… Imanager 3.2.6+ Fix from $2,3002024-05-15 MEDIUM 6.4 CVE-2024-2248 A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over … Mitigation only Fix from $1,6002024-05-15 HIGH 7.8 CVE-2024-34098 Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitr… Acrobat Dc 20.005.30635 / 20.005.30636+ Fix from $1,9502024-05-15 HIGH 7.2 CVE-2021-22280 Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the co… Automation Studio 4.12+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-3676 The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthentic… Mitigation only Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2024-30054 Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability Powerbi Javascript 2.23.1+ Fix from $1,6002024-05-14 HIGH 8.8 CVE-2024-30040 KEV Windows MSHTML Platform Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20651 / 10.0.14393.6981+ Fix from $1,9502024-05-14 MEDIUM 6.8 CVE-2024-30002 Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows 10 1809 10.0.17763.5820 / 10.0.19044.4412+ Fix from $1,6002024-05-14 MEDIUM 6.8 CVE-2024-29998 Windows Mobile Broadband Driver Remote Code Execution Vulnerability Windows 10 1809 10.0.17763.5820 / 10.0.19044.4412+ Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-3372 Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and m… MongoDB 5.0.25 / 6.0.14+ Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2024-25970 Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could pote… Powerscale Onefs 9.4.0.18 / 9.5.0.8+ Fix from $1,6002024-05-14 CRITICAL 9.1 CVE-2024-34365 ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. A… Karaf Cave Mitigation only Fix from $2,3002024-05-14 HIGH 7.5 CVE-2024-32992 Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability. Emui No fix yet Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-32989 Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availab… Emui No fix yet Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-32990 Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availabil… Emui No fix yet Fix from $1,9502024-05-14 MEDIUM 5.3 CVE-2024-32669 Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test cod… Patch available Fix from $1,6002024-05-14 MEDIUM 5.3 CVE-2024-32672 A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via … Patch available Fix from $1,6002024-05-14 HIGH 7.5 CVE-2024-30258 FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.… Fast Dds 2.6.8 / 2.10.4+ Fix from $1,9502024-05-14 CRITICAL 9.1 CVE-2024-2257 This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of passwor… Mitigation only Fix from $2,3002024-05-14 HIGH 7.2 CVE-2024-25641EPSS 86% Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable … Fedora 1.2.27+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-25581 When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker… Mitigation only Fix from $1,9502024-05-14 HIGH 8.4 CVE-2024-1929 Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity v… Dnf5 5.1.17+ Fix from $1,9502024-05-08 HIGH 8.8 CVE-2024-2746 Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unpr… Mitigation only Fix from $1,9502024-05-08 MEDIUM 5.5 CVE-2024-0022 In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profil… Android Patch available Fix from $1,6002024-05-07 HIGH 7.8 CVE-2024-23705 In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23706 In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23707 In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with… Android Patch available Fix from $1,9502024-05-07 HIGH 7.5 CVE-2024-32371 An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administra… Mailinspector 5.2.19+ Fix from $1,9502024-05-07 MEDIUM 5.8 CVE-2023-7240  An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perfo… Mitigation only Fix from $1,6002024-05-07