Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.2 CVE-2023-36505 Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6… Ninja Forms 3.6.25+ Fix from $1,9502024-04-17 MEDIUM 6.1 CVE-2024-3841 Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a p… Chrome 124.0.6367.60+ Fix from $1,6002024-04-17 MEDIUM 5.3 CVE-2022-24806 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can ex… Fedora Patch available Fix from $1,6002024-04-16 HIGH 7.2 CVE-2024-3028 mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipu… Anythingllm 1.0.0+ Fix from $1,9502024-04-16 HIGH 8.0 CVE-2024-3029 In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-use… Anythingllm 1.0.0+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-3493 A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause … Controllogix 5580 Firmware Mitigation only Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-2424 An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverabl… 5015 Aenftxt Firmware Mitigation only Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-29838 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticate… Evolution after 2.04.560 Fix from $1,9502024-04-15 MEDIUM 6.5 CVE-2024-21590 An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper Networks Junos OS Evolved allows an unauthentica… Junos Os Evolved after 21.2 Fix from $1,6002024-04-12 MEDIUM 6.3 CVE-2024-29461 An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component. Open Sdn Controller No fix yet Fix from $1,6002024-04-12 CRITICAL 10.0 CVE-2024-3400 KEVEPSS 100% A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci… Pan Os Mitigation only Fix from $2,3002024-04-12 HIGH 7.1 CVE-2024-30916 An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive info… Fast Dds after 2.14.0 Fix from $1,9502024-04-11 MEDIUM 5.3 CVE-2024-1481 A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command argume… Mitigation only Fix from $1,6002024-04-10 HIGH 7.5 CVE-2024-3385 A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks ev… Pan Os 9.1.17 / 10.1.12+ Fix from $1,9502024-04-10 HIGH 7.2 CVE-2024-3101 In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. … Anythingllm 1.0.0+ Fix from $1,9502024-04-10 HIGH 7.5 CVE-2024-31309EPSS 95% HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0… Traffic Server 8.1.10 / 9.2.4+ Fix from $1,9502024-04-10 CRITICAL 9.0 CVE-2024-20758 Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could r… Commerce Mitigation only Fix from $2,3002024-04-10 MEDIUM 5.3 CVE-2024-21507 Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poison… Mysql2 3.9.3+ Fix from $1,6002024-04-10 MEDIUM 5.4 CVE-2024-2513 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and inclu… Wp Chat App 3.6.3+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2536 The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions … Seo 1.0.215+ Fix from $1,6002024-04-09 MEDIUM 6.4 CVE-2024-2650 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cros… Essential Addons For Elementor 5.9.11+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2226 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… Otter Blocks 2.6.5+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2165 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and i… Seopress 7.6+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2027 The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attribute… Real Media Library 4.22.8+ Fix from $1,6002024-04-09 MEDIUM 5.5 CVE-2024-25116 RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users… Patch available Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-31867 Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties… Zeppelin 0.11.1+ Fix from $1,6002024-04-09 MEDIUM 6.8 CVE-2024-28897 Secure Boot Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,6002024-04-09 MEDIUM 6.8 CVE-2024-26253 Windows rndismp6.sys Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,6002024-04-09 HIGH 8.0 CVE-2024-26240 Secure Boot Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,9502024-04-09 HIGH 8.0 CVE-2024-26189 Secure Boot Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,9502024-04-09