Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Fxos HIGH 7.4
CVE-2021-34714

A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR S…

Fix: 2.2.2.148 / 2.3.1.216+
Fix from $1,950 2021-09-23
Ansible Automation Platform HIGH 7.1
CVE-2021-3583

A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i…

Fix: 2.9.23 / 3.7.0+
Fix from $1,950 2021-09-22
Butter MEDIUM 6.5
CVE-2021-39230

Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are recommend to update to the Trin…

Fix: 1.5+
Fix from $1,600 2021-09-21
Routinator HIGH 7.5
CVE-2021-41531

NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This wil…

Fix: 0.10.0+
Fix from $1,950 2021-09-21
Kubernetes HIGH 8.1
CVE-2021-25741EPSS 8%

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories…

Fix: after 1.22.1
Fix from $1,950 2021-09-20
Vnc Viewer MEDIUM 6.5
CVE-2021-41380

RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserte…

No fix yet
Fix from $1,600 2021-09-17
Flexnet Publisher HIGH 7.5
CVE-2020-12080

A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited…

No fix yet
Fix from $1,950 2021-09-17
Ni Pal HIGH 7.8
CVE-2021-38304

Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable es…

Fix: after 20.0.0
Fix from $1,950 2021-09-17
Apq8009 Firmware HIGH 7.8
CVE-2021-30260

Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration comma…

Mitigation only
Fix from $1,950 2021-09-17
Apq8009 Firmware HIGH 7.8
CVE-2021-30261

Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon…

Mitigation only
Fix from $1,950 2021-09-17
Tomcat HIGH 7.5
CVE-2021-41079EPSS 7%

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured …

Fix: 8.5.64 / 9.0.44+
Fix from $1,950 2021-09-16
Tssservisignadapter CRITICAL 9.8
CVE-2021-37909

WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permis…

Fix: after 1.0.20.0316
Fix from $2,300 2021-09-15
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23028

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configure…

Fix: 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23030

On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all…

Fix: after 16.0.1.1
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23036

On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traf…

Fix: after 16.0.1
Fix from $1,950 2021-09-14
Big Ip Domain Name System HIGH 7.5
CVE-2021-23032

On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is con…

Fix: 14.1.4.4 / 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2021-23033

On BIG-IP Advanced WAF and BIG-IP ASM version 16.x before 16.1.0x, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all ve…

Fix: 13.1.4.1 / 14.1.4.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23034

On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, und…

Fix: 15.1.3.1 / 16.1.0+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23035

On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can…

Fix: after 14.1.4.4
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23039

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a…

Fix: 14.1.2.8 / 15.1.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23045

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an…

Fix: 13.1.4.1 / 14.1.4.3+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23044

On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, …

Fix: 13.1.4.1 / 14.1.4.2+
Fix from $1,950 2021-09-14
Security Secret Server MEDIUM 5.3
CVE-2021-20569

IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243.

Fix: 11.0+
Fix from $1,600 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23051

On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Am…

Fix: 15.1.3.1+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23048

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6…

Fix: 13.1.4.1 / 14.1.4.3+
Fix from $1,950 2021-09-14
Siprotec 5 With Cpu Variant Cp050 HIGH 7.5
CVE-2021-37206

A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (A…

Fix: 8.80+
Fix from $1,950 2021-09-14
Themes HIGH 7.0
CVE-2021-25465

An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.

Fix: 5.2.01+
Fix from $1,950 2021-09-09
Android MEDIUM 5.5
CVE-2021-25453

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 6.5
CVE-2021-25450

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socke…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25452

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent …

Mitigation only
Fix from $1,600 2021-09-09