Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2023-49248 Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access. Emui No fix yet Fix from $1,6002023-12-06 MEDIUM 5.0 CVE-2023-40053 A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Ser… Serv U Mitigation only Fix from $1,6002023-12-06 CRITICAL 9.8 CVE-2023-41268 Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: fr… Escargot Patch available Fix from $2,3002023-12-06 HIGH 7.5 CVE-2023-5188 The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An… Telecontrol Configurator 1.4.6.0+ Fix from $1,9502023-12-05 HIGH 7.5 CVE-2023-33042 Transient DOS in Modem after RRC Setup message is received. 315 5g Iot Modem Firmware Mitigation only Fix from $1,9502023-12-05 CRITICAL 9.8 CVE-2023-48693 Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arb… Azure Rtos Threadx 6.3.0+ Fix from $2,3002023-12-05 CRITICAL 9.8 CVE-2023-49291 tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions … Branch Names 7.0.0 / 7.0.7+ Fix from $2,3002023-12-05 HIGH 7.8 CVE-2023-40097 In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local es… Android Patch available Fix from $1,9502023-12-04 MEDIUM 6.5 CVE-2023-47106 Traefik is an open source HTTP reverse proxy and load balancer. When a request is sent to Traefik with a URL fragment, Traefik automatically URL enco… Traefik after 2.10.5 Fix from $1,6002023-12-04 HIGH 7.5 CVE-2023-40687 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RU… Db2 after 11.5.9 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-29258 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted fed… Db2 after 11.5.9 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-38727 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQ… Db2 after 11.5.9 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-46167 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted… Db2 after 11.5.8 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-47701 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu… Db2 after 11.5.9 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-45178 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a specially crafted request is u… Db2 Patch available Fix from $1,9502023-12-03 HIGH 7.5 CVE-2023-40699 IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: … Infosphere Information Server 11.7.1.0 / 11.7.1.4+ Fix from $1,9502023-12-01 MEDIUM 6.5 CVE-2023-34390 An input validation vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authenticated attacker to create a denial o… Sel 451 Firmware Mitigation only Fix from $1,6002023-11-30 MEDIUM 5.4 CVE-2023-2267 An Improper Input Validation vulnerability in Schweitzer Engineering Laboratories SEL-411L could allow an attacker to perform reflection attacks agai… Sel 411l Firmware No fix yet Fix from $1,6002023-11-30 HIGH 7.8 CVE-2023-2264 An improper input validation vulnerability in the Schweitzer Engineering Laboratories SEL-411L could allow a malicious actor to manipulate authorized… Sel 411l Firmware No fix yet Fix from $1,9502023-11-30 HIGH 7.5 CVE-2023-49095 nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another use… Nexkey 12.122.2+ Fix from $1,9502023-11-30 MEDIUM 5.3 CVE-2023-49081 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HT… Aiohttp 3.9.0+ Fix from $1,6002023-11-30 MEDIUM 5.3 CVE-2023-49082 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the H… Aiohttp 3.9.0+ Fix from $1,6002023-11-29 MEDIUM 5.5 CVE-2023-35136 An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmw… Zld after 5.37 Fix from $1,6002023-11-28 HIGH 7.5 CVE-2023-48310 TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtered correctly. Nmap options are… Testing Platform 2.1.1+ Fix from $1,9502023-11-20 MEDIUM 5.9 CVE-2023-48223 fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm conf… Fast Jwt 3.3.2+ Fix from $1,6002023-11-20 MEDIUM 5.3 CVE-2023-26364 @adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service … Css Tools 4.3.1+ Fix from $1,6002023-11-17 HIGH 7.5 CVE-2023-22272 Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure … Robohelp Server after 11.4 Fix from $1,9502023-11-17 MEDIUM 6.1 CVE-2023-40314 Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session informat… Horizon 32.0.5 / 2023.1.9+ Fix from $1,6002023-11-16 MEDIUM 6.7 CVE-2023-32469 Dell Precision Tower BIOS contains an Improper Input Validation vulnerability. A locally authenticated malicious user with admin privileges could pot… Precision 5820 Firmware 2.32.0 / 2.36.0+ Fix from $1,6002023-11-16 CRITICAL 9.8 CVE-2023-47003 An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsD… Redisgraph No fix yet Fix from $2,3002023-11-16