Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2023-31289 Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort. Pexip Infinity 31.2+ Fix from $1,9502023-12-25 HIGH 7.5 CVE-2023-31455 Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. Pexip Infinity 31.2+ Fix from $1,9502023-12-25 MEDIUM 6.7 CVE-2023-39251 Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerabili… Inspiron 7510 Firmware 1.20.0 / 1.23.0+ Fix from $1,6002023-12-22 MEDIUM 5.5 CVE-2023-45165 IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-For… Aix Mitigation only Fix from $1,6002023-12-22 MEDIUM 6.8 CVE-2023-0011 A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This v… Toby L200 Firmware Mitigation only Fix from $1,6002023-12-20 MEDIUM 5.5 CVE-2023-42012 An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject… Urbancode Deploy after 7.3.2.2 Fix from $1,6002023-12-20 MEDIUM 6.5 CVE-2023-47161 IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive f… Urbancode Deploy after 7.3.2.2 Fix from $1,6002023-12-20 MEDIUM 5.5 CVE-2023-45172 IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X… Vios Patch available Fix from $1,6002023-12-19 HIGH 7.2 CVE-2023-39509 A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o… Cpp13 Firmware after 8.90 Fix from $1,9502023-12-18 CRITICAL 9.8 CVE-2023-32728 The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f… Zabbix Agent2 after 6.4.8 Fix from $2,3002023-12-18 HIGH 7.2 CVE-2023-32727 An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitr… Zabbix Server after 6.4.7 Fix from $1,9502023-12-18 HIGH 8.8 CVE-2023-46116 Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.1… Tutanota 3.118.12+ Fix from $1,9502023-12-15 HIGH 7.5 CVE-2023-33217 By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the ter… Sigma Lite Firmware 1.2.7 / 2.12.2+ Fix from $1,9502023-12-15 MEDIUM 5.3 CVE-2023-6835 Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum feature, API rating could be manip… Api Manager Mitigation only Fix from $1,6002023-12-15 HIGH 7.5 CVE-2023-48631 @adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while… Css Tools 4.3.2+ Fix from $1,9502023-12-14 HIGH 8.0 CVE-2023-25651 There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an auth… Mf833u1 Firmware Mitigation only Fix from $1,9502023-12-14 MEDIUM 6.5 CVE-2023-25650 There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker w… Zxcloud Irai 7.23.30+ Fix from $1,6002023-12-14 HIGH 7.5 CVE-2023-50709 Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitti… Cube.js 0.34.34+ Fix from $1,9502023-12-13 HIGH 7.5 CVE-2023-50262 Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that paths within the SVG are all… Dompdf after 2.0.3 Fix from $1,9502023-12-13 HIGH 7.8 CVE-2023-48634 Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could resu… After Effects after 24.0.3 Fix from $1,9502023-12-13 MEDIUM 5.5 CVE-2023-6381 Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerabili… Supermailer Mitigation only Fix from $1,6002023-12-13 MEDIUM 5.3 CVE-2023-35619 Microsoft Outlook for Mac Spoofing Vulnerability Office Long Term Servicing Channel Patch available Fix from $1,6002023-12-12 HIGH 7.5 CVE-2023-46285 A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo… Opcenter Quality 4.1 / 15+ Fix from $1,9502023-12-12 MEDIUM 5.3 CVE-2023-49796 MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file write vulnerability in `file.py… Mindsdb Patch available Fix from $1,6002023-12-11 CRITICAL 9.8 CVE-2023-48425 U-Boot vulnerability resulting in persistent Code Execution  Chromecast Firmware 2023-10-01+ Fix from $2,3002023-12-11 HIGH 7.5 CVE-2023-6245 The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `rec… Candid 0.9.10+ Fix from $1,9502023-12-08 HIGH 7.8 CVE-2023-5058 Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows… Securecore Technology Mitigation only Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-49958 An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandl… Open Charge Point Protocol after 1.2.0 Fix from $1,9502023-12-07 HIGH 7.8 CVE-2023-39538 AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A s… Aptio V Mitigation only Fix from $1,9502023-12-06 HIGH 7.8 CVE-2023-39539 AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A s… Aptio V Mitigation only Fix from $1,9502023-12-06