Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2024-21476 Memory corruption when the channel ID passed by user is not validated and further used. Aqt1000 Firmware Mitigation only Fix from $1,9502024-05-06 CRITICAL 9.8 CVE-2024-4547 A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is sp… Diaenergie 1.10.01.004+ Fix from $2,3002024-05-06 CRITICAL 9.8 CVE-2024-4548EPSS 29% An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is s… Diaenergie 1.10.01.004+ Fix from $2,3002024-05-06 MEDIUM 6.7 CVE-2024-20056 In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with Sys… Rdk B Mitigation only Fix from $1,6002024-05-06 HIGH 7.8 CVE-2024-20064 In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no a… Android Mitigation only Fix from $1,9502024-05-06 MEDIUM 5.3 CVE-2024-34473 An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration … Mitigation only Fix from $1,6002024-05-04 CRITICAL 9.8 CVE-2024-33792 netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page. Mex605 Firmware No fix yet Fix from $2,3002024-05-03 HIGH 7.5 CVE-2023-40515 LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial… Simple Editor Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.5 CVE-2023-32170 Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to c… Uagateway 1.5.13.487+ Fix from $1,6002024-05-03 MEDIUM 5.4 CVE-2024-4003 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cros… Essential Addons For Elementor 5.9.16+ Fix from $1,6002024-05-02 MEDIUM 5.4 CVE-2024-3747 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the className parameter in the About Me block in all versions up to,… Blocksy 2.0.40+ Fix from $1,6002024-05-02 MEDIUM 5.4 CVE-2024-2867 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul… Profilepress 4.15.5+ Fix from $1,6002024-05-02 MEDIUM 5.4 CVE-2024-2751 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ para… Exclusive Addons For Elementor 2.6.9.3+ Fix from $1,6002024-05-02 HIGH 8.0 CVE-2024-25290 An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function. Mitigation only Fix from $1,9502024-05-02 MEDIUM 5.3 CVE-2024-0710 The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficien… Mitigation only Fix from $1,6002024-05-02 CRITICAL 9.0 CVE-2024-4142 An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vuln… Mitigation only Fix from $2,3002024-05-01 MEDIUM 6.5 CVE-2024-3096 In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00… PHP 8.1.28 / 8.2.18+ Fix from $1,6002024-04-29 MEDIUM 6.5 CVE-2024-2756EPSS 38% Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard in… Mitigation only Fix from $1,6002024-04-29 MEDIUM 5.3 CVE-2024-32645 Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_… Vyper 0.4.0+ Fix from $1,6002024-04-25 MEDIUM 5.3 CVE-2024-32646 Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `slice` builtin can result in a… Vyper 0.4.0+ Fix from $1,6002024-04-25 HIGH 7.8 CVE-2024-28240 The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI packaging can allow a local u… Glpi Agent 1.7.2+ Fix from $1,9502024-04-25 MEDIUM 5.4 CVE-2024-4175 Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to send a malicious payload wit… Mitigation only Fix from $1,6002024-04-25 HIGH 7.5 CVE-2024-25583 A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The … Mitigation only Fix from $1,9502024-04-25 HIGH 7.8 CVE-2024-28976 Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could p… Repository Manager 3.4.5+ Fix from $1,9502024-04-24 MEDIUM 5.5 CVE-2024-28977 Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low privileges … Repository Manager after 3.4.4 Fix from $1,6002024-04-24 MEDIUM 6.1 CVE-2024-32653 jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject ar… Mitigation only Fix from $1,6002024-04-22 HIGH 7.3 CVE-2023-38293 Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone… Mitigation only Fix from $1,9502024-04-22 HIGH 7.5 CVE-2024-31841 An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbi… Embrace No fix yet Fix from $1,9502024-04-19 HIGH 7.2 CVE-2024-3646 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.9.13 / 3.10.10+ Fix from $1,9502024-04-19 HIGH 8.1 CVE-2023-5397 Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See … No fix yet Fix from $1,9502024-04-17