Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.0 CVE-2021-33142 Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user… Ethernet Controller I225 It Firmware 1.87 / 29.0.1+ Fix from $1,6002024-02-23 MEDIUM 5.3 CVE-2021-33146 Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticate… Ethernet Controller I225 It Firmware 1.87 / 29.0.1+ Fix from $1,6002024-02-23 HIGH 7.2 CVE-2021-33161 Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user… Ethernet Controller I225 It Firmware 1.87 / 29.0.1+ Fix from $1,9502024-02-23 HIGH 8.8 CVE-2024-23320 Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed … Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-23 MEDIUM 5.4 CVE-2024-26151 The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mail… Mjml Python Patch available Fix from $1,6002024-02-22 HIGH 7.1 CVE-2024-1714 An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or traili… Identityiq Mitigation only Fix from $1,9502024-02-21 HIGH 7.5 CVE-2024-22054 A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management … Mitigation only Fix from $1,9502024-02-20 MEDIUM 5.4 CVE-2024-25973 The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit gr… Openolat 18.1.6+ Fix from $1,6002024-02-20 MEDIUM 5.4 CVE-2024-25974 The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Cente… Openolat 18.1.6+ Fix from $1,6002024-02-20 CRITICAL 9.1 CVE-2024-1638 The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write … Zephyr after 3.5.0 Fix from $2,3002024-02-19 MEDIUM 5.3 CVE-2023-52368 Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally. Emui No fix yet Fix from $1,6002024-02-18 HIGH 7.5 CVE-2023-52372 Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affect availability. Emui Mitigation only Fix from $1,9502024-02-18 HIGH 7.8 CVE-2024-0021 In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener se… Android Patch available Fix from $1,9502024-02-16 HIGH 7.5 CVE-2023-51931 An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function. Urlite after 3.1.0 Fix from $1,9502024-02-16 CRITICAL 9.8 CVE-2024-0031 In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead t… Android Patch available Fix from $2,3002024-02-16 MEDIUM 5.3 CVE-2023-6937 wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS me… Wolfssl 5.6.6+ Fix from $1,6002024-02-15 MEDIUM 5.5 CVE-2024-20733 Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an appli… Acrobat Dc 20.005.30574 / 23.008.20533+ Fix from $1,6002024-02-15 CRITICAL 9.8 CVE-2023-32462 Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remot… Smartfabric Os10 10.5.2.12 / 10.5.3.8+ Fix from $2,3002024-02-15 CRITICAL 9.8 CVE-2023-32484 Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remot… Enterprise Sonic Distribution 3.5.5 / 4.0.6+ Fix from $2,3002024-02-15 MEDIUM 5.5 CVE-2023-42776 Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially en… Sgx Dcap 1.19.100.3+ Fix from $1,6002024-02-14 MEDIUM 6.5 CVE-2023-34983 Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated… Killer 3.1423.712 / 22.240+ Fix from $1,6002024-02-14 MEDIUM 6.5 CVE-2023-28374 Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated… Killer 3.1423.712 / 22.240+ Fix from $1,6002024-02-14 MEDIUM 6.7 CVE-2023-25951 Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user … Killer 3.1423.712 / 22.240+ Fix from $1,6002024-02-14 HIGH 7.7 CVE-2023-22342 Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially e… Thunderbolt Dch Driver 88+ Fix from $1,9502024-02-14 MEDIUM 6.5 CVE-2024-24695 Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticate… Meeting Software Development Kit 5.15.15 / 5.16.5+ Fix from $1,6002024-02-14 MEDIUM 6.5 CVE-2024-24696 Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticate… Meeting Software Development Kit 5.15.15 / 5.16.12+ Fix from $1,6002024-02-14 CRITICAL 9.1 CVE-2024-1369 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1372 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1374 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1378 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13