Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Fisco Bcos HIGH 7.5
CVE-2021-35041

The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet …

Patch available
Fix from $1,950 2021-06-24
S12700 Firmware HIGH 7.2
CVE-2021-22377

There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and…

Mitigation only
Fix from $1,950 2021-06-22
Form MEDIUM 5.3
CVE-2021-32697

neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted…

Fix: 4.3.3 / 5.0.9+
Fix from $1,600 2021-06-21
Android HIGH 7.8
CVE-2021-0511

In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalatio…

Patch available
Fix from $1,950 2021-06-21
Jabber MEDIUM 6.5
CVE-2021-1569

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access s…

Fix: 12.9.6.55898 / 14.0.1.55914+
Fix from $1,600 2021-06-16
Jabber MEDIUM 6.5
CVE-2021-1570

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access s…

Fix: 12.9.6.55898 / 14.0.1.55914+
Fix from $1,600 2021-06-16
Meeting Server MEDIUM 6.5
CVE-2021-1524

A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an a…

Fix: 3.1.1+
Fix from $1,600 2021-06-16
Insydeh2o MEDIUM 6.7
CVE-2020-27339

In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers …

Fix: 5.16.25 / 5.25.44+
Fix from $1,600 2021-06-16
Sinamics Sl150 Firmware CRITICAL 9.8
CVE-2021-27388

SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthen…

Mitigation only
Fix from $2,300 2021-06-15
Relion 670 Firmware HIGH 7.5
CVE-2021-27196

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, RE…

Fix: 1.2.3.20 / 1.3.0.7+
Fix from $1,950 2021-06-14
Poweredge R640 Firmware MEDIUM 6.7
CVE-2021-21557

Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high …

Fix: 2.11.2+
Fix from $1,600 2021-06-14
Radeon Pro Software HIGH 7.8
CVE-2020-12985

An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

Fix: 20.7.1 / 21.q1+
Fix from $1,950 2021-06-11
Radeon Pro Software HIGH 7.8
CVE-2020-12986

An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading …

Fix: 20.7.1 / 21.q1+
Fix from $1,950 2021-06-11
Android HIGH 7.8
CVE-2021-0481

In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could le…

Patch available
Fix from $1,950 2021-06-11
Android HIGH 7.8
CVE-2021-0485

In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This co…

Patch available
Fix from $1,950 2021-06-11
Powerlogic Egx100 Firmware CRITICAL 9.8
CVE-2021-22765

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $2,300 2021-06-11
Powerlogic Egx100 Firmware HIGH 7.5
CVE-2021-22766

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $1,950 2021-06-11
Powerlogic Egx100 Firmware CRITICAL 9.8
CVE-2021-22767

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $2,300 2021-06-11
Powerlogic Egx100 Firmware CRITICAL 9.8
CVE-2021-22768

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $2,300 2021-06-11
Android HIGH 7.1
CVE-2021-25410

Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an esc…

No fix yet
Fix from $1,950 2021-06-11
Android MEDIUM 5.5
CVE-2021-25413

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbi…

No fix yet
Fix from $1,600 2021-06-11
Android HIGH 7.8
CVE-2021-25414

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary fi…

No fix yet
Fix from $1,950 2021-06-11
Android MEDIUM 5.5
CVE-2021-25415

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ…

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 6.5
CVE-2021-25416

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel…

Mitigation only
Fix from $1,600 2021-06-11
Health HIGH 7.8
CVE-2021-25401

Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.

Fix: 6.16+
Fix from $1,950 2021-06-11
Apport HIGH 7.8
CVE-2021-25682

It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11
Apport HIGH 7.8
CVE-2021-25683

It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11
Apport HIGH 7.8
CVE-2021-25684

It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11
Go Driver MEDIUM 6.5
CVE-2021-20329

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go…

Fix: after 1.5.0
Fix from $1,600 2021-06-10
Bios MEDIUM 6.7
CVE-2020-8700

Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via …

Mitigation only
Fix from $1,600 2021-06-09