Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2023-30712 Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity. Android Mitigation only Fix from $1,9502023-09-06 HIGH 8.8 CVE-2023-39357 Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type… Fedora No fix yet Fix from $1,9502023-09-05 HIGH 7.2 CVE-2015-2202 Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS. Airwave 7.7.14.2 / 8.0.7+ Fix from $1,9502023-09-05 MEDIUM 6.5 CVE-2023-34317 An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072.… Oas Platform No fix yet Fix from $1,6002023-09-05 CRITICAL 9.8 CVE-2023-40743 ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "S… Axis 2023-08-01+ Fix from $2,3002023-09-05 MEDIUM 6.5 CVE-2022-43903 IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. I… Security Guardium Patch available Fix from $1,6002023-09-05 MEDIUM 6.7 CVE-2023-32811 In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privi… Yocto Mitigation only Fix from $1,6002023-09-04 HIGH 7.5 CVE-2023-33914 In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosur… Android No fix yet Fix from $1,9502023-09-04 HIGH 7.5 CVE-2023-4698 Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. Memos 0.13.2+ Fix from $1,9502023-09-01 HIGH 7.5 CVE-2023-4481EPSS 15% An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthent… Junos 20.4+ Fix from $1,9502023-09-01 CRITICAL 9.8 CVE-2023-41746 Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.2308… Cloud Manager 6.2.23089.203+ Fix from $2,3002023-08-31 CRITICAL 9.8 CVE-2023-41748 Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.2308… Cloud Manager 6.2.23089.203+ Fix from $2,3002023-08-31 HIGH 7.8 CVE-2023-39137 An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing. Archive No fix yet Fix from $1,9502023-08-30 HIGH 7.5 CVE-2023-26095 ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet. Stormshield Network Security 4.6.3+ Fix from $1,9502023-08-28 HIGH 8.8 CVE-2023-27604 Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, wh… Airflow Sqoop Provider 4.0.0+ Fix from $1,9502023-08-28 HIGH 8.8 CVE-2023-40797 In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack… Ac23 Firmware No fix yet Fix from $1,9502023-08-25 HIGH 8.8 CVE-2023-40798 In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post… Ac23 Firmware No fix yet Fix from $1,9502023-08-25 HIGH 8.8 CVE-2023-40800 The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability … Ac23 Firmware No fix yet Fix from $1,9502023-08-25 HIGH 8.8 CVE-2023-40801 The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_… Ac23 No fix yet Fix from $1,9502023-08-25 HIGH 7.5 CVE-2023-3705 The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthent… Cp Vnr 3104 Firmware Patch available Fix from $1,9502023-08-24 MEDIUM 5.3 CVE-2023-3704 The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An un… Cp Uvr 1601e1 Hc Firmware 4.000.00at008.0.0.r20230302+ Fix from $1,6002023-08-24 MEDIUM 6.5 CVE-2023-20168 A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affec… Nx Os Mitigation only Fix from $1,6002023-08-23 HIGH 7.4 CVE-2023-20169 A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches a… Nx Os Mitigation only Fix from $1,9502023-08-23 HIGH 8.8 CVE-2023-25915 Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system. Ak Sm 800a Firmware after 3.3 Fix from $1,9502023-08-21 MEDIUM 5.3 CVE-2023-36674 An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possi… Mediawiki 1.35.11 / 1.38.7+ Fix from $1,6002023-08-20 MEDIUM 5.5 CVE-2023-4435 Improper Input Validation in GitHub repository hamza417/inure prior to build88. Inure Patch available Fix from $1,6002023-08-20 HIGH 7.5 CVE-2023-40165 rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any upl… Rubygems.org 2023-08-14+ Fix from $1,9502023-08-17 HIGH 7.5 CVE-2023-2914EPSS 40% The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the… Thinmanager Thinserver after 13.0.2 Fix from $1,9502023-08-17 CRITICAL 9.1 CVE-2023-2915EPSS 84% The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path tr… Thinmanager Thinserver after 13.0.2 Fix from $2,3002023-08-17 CRITICAL 9.8 CVE-2023-2917EPSS 72% The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a pat… Thinmanager Thinserver after 13.0.2 Fix from $2,3002023-08-17