Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2023-28574 Memory corruption in core services when Diag handler receives a command to configure event listeners. Ar8035 Firmware No fix yet Fix from $1,9502023-11-07 HIGH 7.8 CVE-2023-21671 Memory Corruption in Core during syscall for Sectools Fuse comparison feature. Fastconnect 6700 Firmware No fix yet Fix from $1,9502023-11-07 HIGH 7.2 CVE-2023-5964 The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly valida… Platform 23.0+ Fix from $1,9502023-11-06 HIGH 7.2 CVE-2023-45161 The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL … Platform 20.1+ Fix from $1,9502023-11-06 HIGH 7.2 CVE-2023-45163 The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the inpu… Platform 18.1+ Fix from $1,9502023-11-06 HIGH 8.8 CVE-2023-3893 A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escala… Csi Proxy after 1.1.2 Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-4043 In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-… Parsson 1.0.5 / 1.1.4+ Fix from $1,9502023-11-03 CRITICAL 9.8 CVE-2023-5763 In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious c… Glassfish after 6.2.5 Fix from $2,3002023-11-03 CRITICAL 9.8 CVE-2023-41355 Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attac… G 040w Q Firmware Mitigation only Fix from $2,3002023-11-03 CRITICAL 9.8 CVE-2023-42802 GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation … Glpi 10.0.10+ Fix from $2,3002023-11-02 MEDIUM 5.3 CVE-2023-20255 A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of serv… Meeting Server 3.6.1+ Fix from $1,6002023-11-01 HIGH 8.2 CVE-2023-20063 A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devic… Secure Firewall Management Center after 7.3.1.1 Fix from $1,9502023-11-01 MEDIUM 6.5 CVE-2023-20114 A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to dow… Secure Firewall Management Center after 7.3.1.1 Fix from $1,6002023-11-01 MEDIUM 5.8 CVE-2023-20270 A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower … Secure Firewall Threat Defense Mitigation only Fix from $1,6002023-11-01 HIGH 8.8 CVE-2023-40061  Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result. Solarwinds Platform 2023.4+ Fix from $1,9502023-11-01 HIGH 8.8 CVE-2023-40062 SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privi… Solarwinds Platform 2023.4+ Fix from $1,9502023-11-01 MEDIUM 5.5 CVE-2022-48457 In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional exec… Android Mitigation only Fix from $1,6002023-11-01 MEDIUM 5.5 CVE-2022-48458 In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional exec… Android Mitigation only Fix from $1,6002023-11-01 MEDIUM 5.5 CVE-2022-48459 In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional exec… Android Mitigation only Fix from $1,6002023-11-01 HIGH 8.8 CVE-2023-4197EPSS 33% Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a… Dolibarr Erp\/crm after 18.0.1 Fix from $1,9502023-11-01 HIGH 8.8 CVE-2023-3676EPSS 12% A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho… Kubernetes 1.24.17 / 1.25.13+ Fix from $1,9502023-10-31 HIGH 8.8 CVE-2023-3955 A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho… Kubernetes 1.24.17 / 1.25.13+ Fix from $1,9502023-10-31 HIGH 7.5 CVE-2023-21391 In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of serv… Android 14.0+ Fix from $1,9502023-10-30 MEDIUM 6.7 CVE-2022-4574 An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges t… Thinkpad X13 Yoga Gen 2 Firmware 1.26 / 1.30+ Fix from $1,6002023-10-30 MEDIUM 6.7 CVE-2022-4573 An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to exec… Thinkpad X1 Fold Gen 1 Firmware Mitigation only Fix from $1,6002023-10-30 MEDIUM 6.7 CVE-2022-48189 An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to… Thinkpad E14 Firmware 1.16 / 1.18+ Fix from $1,6002023-10-30 CRITICAL 9.1 CVE-2023-5832 Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. Anythingllm 0.1.0+ Fix from $2,3002023-10-30 MEDIUM 5.4 CVE-2023-42431 Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile i… Bluespice 3.2.10.1 / 4.3.3+ Fix from $1,6002023-10-30 MEDIUM 6.5 CVE-2022-3429 A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, t… Gm265dn Firmware 02.06.00.04.00+ Fix from $1,6002023-10-27 HIGH 7.5 CVE-2023-46289 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious … Factorytalk View after 13.0 Fix from $1,9502023-10-27