Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.0 CVE-2024-1354 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $1,9502024-02-13 CRITICAL 9.1 CVE-2024-1355 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.1 CVE-2024-1359 A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console t… Enterprise Server 3.8.15 / 3.9.10+ Fix from $2,3002024-02-13 CRITICAL 9.8 CVE-2024-21413 KEVEPSS 95% Microsoft Outlook Remote Code Execution Vulnerability 365 Apps Patch available Fix from $2,3002024-02-13 MEDIUM 5.0 CVE-2024-21374 Microsoft Teams for Android Information Disclosure Vulnerability Teams 1.0.0.2024022302+ Fix from $1,6002024-02-13 HIGH 7.8 CVE-2024-21315 Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability Defender For Endpoint 6.2.9200.24569 / 6.2.9200.24710+ Fix from $1,9502024-02-13 MEDIUM 6.5 CVE-2024-20684 Windows Hyper-V Denial of Service Vulnerability Windows 11 21h2 10.0.20348.2322 / 10.0.22000.2777+ Fix from $1,6002024-02-13 HIGH 7.5 CVE-2024-23324 Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can forc… Envoy 1.26.7 / 1.27.3+ Fix from $1,9502024-02-09 MEDIUM 5.4 CVE-2024-22119 The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. Zabbix 5.0.40 / 6.0.24+ Fix from $1,6002024-02-09 MEDIUM 5.3 CVE-2024-24941 In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL Intellij Idea 2023.3.3+ Fix from $1,6002024-02-06 HIGH 7.5 CVE-2023-33057 Transient DOS in Multi-Mode Call Processor while processing UE policy container. 315 5g Iot Modem Firmware No fix yet Fix from $1,9502024-02-06 HIGH 7.5 CVE-2023-47355 The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff,… Root Quick Reboot No fix yet Fix from $1,9502024-02-05 HIGH 7.5 CVE-2024-20003 In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid N… Nr15 Mitigation only Fix from $1,9502024-02-05 HIGH 7.5 CVE-2024-20004 In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid N… Nr15 Mitigation only Fix from $1,9502024-02-05 MEDIUM 6.2 CVE-2024-21863 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input. Openharmony after 3.2.4 Fix from $1,6002024-02-02 MEDIUM 5.5 CVE-2024-0285 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input. Openharmony after 3.2.4 Fix from $1,6002024-02-02 MEDIUM 6.5 CVE-2023-46159 IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 26… Storage Ceph Patch available Fix from $1,6002024-02-02 HIGH 8.1 CVE-2023-49610 MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message run… Feverwarn Firmware Mitigation only Fix from $1,9502024-02-01 MEDIUM 6.5 CVE-2024-21388EPSS 32% Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Edge Chromium 121.0.2277.83+ Fix from $1,6002024-01-30 HIGH 8.6 CVE-2024-1019 ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSec… Modsecurity 3.0.12+ Fix from $1,9502024-01-30 HIGH 7.1 CVE-2023-4552 Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with th… Appbuilder 23.2+ Fix from $1,9502024-01-29 MEDIUM 5.3 CVE-2023-4553 Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are view… Appbuilder 23.2+ Fix from $1,6002024-01-29 HIGH 7.5 CVE-2023-4550 Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe Sy… Appbuilder 23.2+ Fix from $1,9502024-01-29 HIGH 8.8 CVE-2023-4551 Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionali… Appbuilder 23.2+ Fix from $1,9502024-01-29 CRITICAL 9.8 CVE-2024-23790 Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. T… Otrs 7.0.49 / 2024.1.1+ Fix from $2,3002024-01-29 MEDIUM 5.3 CVE-2024-23655 Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so th… Tutanota 3.119.10+ Fix from $1,6002024-01-25 HIGH 7.5 CVE-2024-23641 SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `R… Adapter Node 2.1.2 / 2.4.3+ Fix from $1,9502024-01-24 HIGH 7.5 CVE-2024-23842 Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Lguvr 16h Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22770 Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Hvr 16781 Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22771 Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Lguvr 4h Firmware 4.03+ Fix from $1,9502024-01-23