Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Snudown MEDIUM 6.5
CVE-2021-41168

Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affected versions snudown was foun…

Fix: 1.7.0+
Fix from $1,600 2021-10-21
Unified Computing System HIGH 7.5
CVE-2021-34736

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote…

Fix: 4.1 / 4.2+
Fix from $1,950 2021-10-21
Qca6174a Firmware HIGH 7.8
CVE-2021-30305

Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdragon Connectivity, Snapdragon…

Patch available
Fix from $1,950 2021-10-20
Apq8009 Firmware HIGH 7.5
CVE-2021-30310

Possible buffer overflow due to Improper validation of received CF-ACK and CF-Poll data frames in Snapdragon Auto, Snapdragon Connectivity, Snapdrago…

Mitigation only
Fix from $1,950 2021-10-20
Aqt1000 Firmware MEDIUM 5.5
CVE-2021-1968

Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user spa…

Patch available
Fix from $1,600 2021-10-20
Aqt1000 Firmware MEDIUM 5.5
CVE-2021-1969

Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user spa…

Patch available
Fix from $1,600 2021-10-20
Junos HIGH 8.8
CVE-2021-31372

An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their priv…

Fix: after 18.2
Fix from $1,950 2021-10-19
Junos MEDIUM 5.4
CVE-2021-31373

A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated us…

Mitigation only
Fix from $1,600 2021-10-19
Junos MEDIUM 5.3
CVE-2021-31375

An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation…

Mitigation only
Fix from $1,600 2021-10-19
Junos HIGH 7.5
CVE-2021-31376

An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to caus…

Mitigation only
Fix from $1,950 2021-10-19
Junos HIGH 7.1
CVE-2021-31360

An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-priv…

Fix: after 20.3
Fix from $1,950 2021-10-19
Frontier MEDIUM 5.3
CVE-2021-41138

Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pallet-ethereum`, a large part …

Fix: 2021-10-13+
Fix from $1,600 2021-10-13
Check Smart HIGH 7.1
CVE-2021-42257

check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /d…

Fix: 6.9.1+
Fix from $1,950 2021-10-11
Java MEDIUM 6.7
CVE-2021-25738

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

Fix: 11.0.1+
Fix from $1,600 2021-10-11
Debian Linux HIGH 7.8
CVE-2021-41133

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak …

Fix: 1.8.2 / 1.10.4+
Fix from $1,950 2021-10-08
Asyncos MEDIUM 5.3
CVE-2021-1534

A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat…

Fix: 14.0.1+
Fix from $1,600 2021-10-06
Android HIGH 8.0
CVE-2021-25485

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote so…

Mitigation only
Fix from $1,950 2021-10-06
Android MEDIUM 5.5
CVE-2021-25489 KEV

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug …

Mitigation only
Fix from $1,600 2021-10-06
Android HIGH 7.5
CVE-2021-25471

A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network c…

Mitigation only
Fix from $1,950 2021-10-06
TYPO3 MEDIUM 5.3
CVE-2021-41114

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that TYPO3 CMS is susceptible to h…

Fix: 11.5.0+
Fix from $1,600 2021-10-05
PHP MEDIUM 5.3
CVE-2021-21705

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with …

Fix: 7.3.29 / 7.4.21+
Fix from $1,600 2021-10-04
Floodlight CRITICAL 9.8
CVE-2020-18683

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.

Fix: after 1.2
Fix from $2,300 2021-09-30
Floodlight CRITICAL 9.8
CVE-2020-18685

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP…

Fix: after 1.2
Fix from $2,300 2021-09-30
Creative Cloud Desktop Application HIGH 7.8
CVE-2021-28547

Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a n…

Fix: after 5.3
Fix from $1,950 2021-09-29
Chengming 3990 Firmware MEDIUM 6.7
CVE-2021-36283

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by usi…

Fix: 1.1.0 / 1.3.1+
Fix from $1,600 2021-09-28
Experience Manager MEDIUM 6.5
CVE-2021-40712

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authentica…

Fix: after 6.5.9.0
Fix from $1,600 2021-09-27
Meeting Connector HIGH 7.2
CVE-2021-34414

The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meetin…

Fix: 2.5.5495.20210326 / 3.8.42.20200905+
Fix from $1,950 2021-09-27
Meeting Connector CRITICAL 9.8
CVE-2021-34416

The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Mee…

Fix: 2.5.5495.20210326 / 3.8.44.20210326+
Fix from $2,300 2021-09-27
Plcnext Technology Starterkit Firmware HIGH 7.5
CVE-2021-34570

Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.

Fix: 2021.0.5+
Fix from $1,950 2021-09-27
Vpn User Portal MEDIUM 6.5
CVE-2021-41583

vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to …

Fix: 2.3.14+
Fix from $1,600 2021-09-24