Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.2 CVE-2023-5624 Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter paramete… Nessus Network Monitor 6.3.0+ Fix from $1,9502023-10-26 HIGH 8.8 CVE-2023-5043 Ingress nginx annotation injection causes arbitrary command execution. Ingress Nginx 1.9.0+ Fix from $1,9502023-10-25 HIGH 8.8 CVE-2023-5044EPSS 57% Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. Ingress Nginx 1.9.0+ Fix from $1,9502023-10-25 MEDIUM 6.5 CVE-2022-4886 Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. Ingress Nginx 1.8.0+ Fix from $1,6002023-10-25 HIGH 7.8 CVE-2021-26736 Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low … Client Connector 3.6+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2023-45805 pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could all… Pdm 0.11.2 / 2.10.0+ Fix from $1,9502023-10-20 HIGH 7.5 CVE-2023-39456EPSS 53% Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 th… Traffic Server 9.2.3+ Fix from $1,9502023-10-17 HIGH 7.1 CVE-2021-29913 IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due t… Security Verify Privilege On Premises 11.5+ Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-40372 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement usin… Db2 after 11.5.8 Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-40373 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common… Db2 after 11.5.8 Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-30991 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. I… Db2 after 11.5.8 Fix from $1,9502023-10-16 HIGH 7.5 CVE-2023-40374 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted query statement. … Db2 after 11.5.8 Fix from $1,9502023-10-16 HIGH 7.5 CVE-2023-38740 IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted SQL statement. … Db2 after 11.5.8 Fix from $1,9502023-10-16 HIGH 7.5 CVE-2023-38728 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted XM… Db2 11.5.8+ Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-45128 Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w… Fiber 2.50.0+ Fix from $1,9502023-10-16 HIGH 7.5 CVE-2023-30987 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu… Db2 11.5.8+ Fix from $1,9502023-10-16 HIGH 7.5 CVE-2023-38720 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with a specially crafted ALTER TAB… Db2 11.5.8+ Fix from $1,9502023-10-16 MEDIUM 5.5 CVE-2023-5421 An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute… Otrs 7.0.47 / 8.0.37+ Fix from $1,6002023-10-16 MEDIUM 5.5 CVE-2023-45176 IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.10.0 and IBM Integration Bus 10.1 through 10.1.0.1 are vulnerable to a d… App Connect Enterprise after 12.0.10.0 Fix from $1,6002023-10-14 CRITICAL 9.1 CVE-2023-29464EPSS 10% FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa… Factorytalk Linx Mitigation only Fix from $2,3002023-10-13 HIGH 7.5 CVE-2023-5571 Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0. Vrite 0.3.0+ Fix from $1,9502023-10-13 MEDIUM 6.5 CVE-2023-44204 An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolve… Junos Mitigation only Fix from $1,6002023-10-13 HIGH 7.5 CVE-2023-44185 An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (… Junos 20.4+ Fix from $1,9502023-10-13 HIGH 7.5 CVE-2023-44192 An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based atta… Junos 20.4+ Fix from $1,9502023-10-13 MEDIUM 5.3 CVE-2023-44183 An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series … Junos Mitigation only Fix from $1,6002023-10-13 MEDIUM 5.4 CVE-2023-32721 A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL. Zabbix after 6.4.5 Fix from $1,6002023-10-12 HIGH 7.5 CVE-2023-44103 Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,9502023-10-11 MEDIUM 5.3 CVE-2023-45648EPSS 6% Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 thro… Tomcat 8.5.94 / 9.0.81+ Fix from $1,6002023-10-10 HIGH 7.8 CVE-2023-36731EPSS 8% Win32k Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 8.0 CVE-2023-36697 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10