Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Efi Bios 7215 HIGH 8.8
CVE-2021-0070

Improper input validation in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthent…

Mitigation only
Fix from $1,950 2021-06-09
Jhl6240 Thunderbolt 3 Firmware MEDIUM 5.5
CVE-2020-12295

Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via lo…

Fix: 21 / 22+
Fix from $1,600 2021-06-09
Bios MEDIUM 5.5
CVE-2020-24486

Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via lo…

Patch available
Fix from $1,600 2021-06-09
Brocade Sannav HIGH 7.5
CVE-2020-15379

Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of …

Fix: after 2.1.0
Fix from $1,950 2021-06-09
Cpp4 Firmware CRITICAL 9.8
CVE-2021-23853

In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.

Mitigation only
Fix from $2,300 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27638

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of …

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27639

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of …

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27640

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27641

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27642

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27643

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-33659

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-33660

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-33661

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09
Aqt1000 Firmware HIGH 7.8
CVE-2020-11178

Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memor…

Mitigation only
Fix from $1,950 2021-06-09
Apq8009 Firmware HIGH 7.8
CVE-2020-11261 KEV

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdrago…

Patch available
Fix from $1,950 2021-06-09
Silverstripe MEDIUM 5.3
CVE-2020-26138

In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.

Fix: 4.6.0+
Fix from $1,600 2021-06-08
Rabbitmq HIGH 7.5
CVE-2021-22116

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e…

Fix: 3.8.16+
Fix from $1,950 2021-06-08
Linux Kernel HIGH 7.8
CVE-2021-3490EPSS 27%

The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned int…

Fix: 5.10.37 / 5.11.21+
Fix from $1,950 2021-06-04
Wire MEDIUM 6.5
CVE-2021-32666

wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulnerability exists that can cause…

Fix: 3.81+
Fix from $1,600 2021-06-03
Singularity MEDIUM 6.3
CVE-2021-32635

Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`…

Mitigation only
Fix from $1,600 2021-05-28
Diagnostic Log And Trace MEDIUM 6.5
CVE-2021-29507

GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file c…

Fix: after 2.18.6
Fix from $1,600 2021-05-28
Fedora CRITICAL 9.4
CVE-2021-32642

radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-edu…

Fix: 1.9.0+
Fix from $2,300 2021-05-28
FreeBSD HIGH 7.5
CVE-2021-29629

In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE befo…

Mitigation only
Fix from $1,950 2021-05-28
Fedora MEDIUM 6.5
CVE-2021-33620EPSS 80%

Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP respons…

Fix: 4.15 / 5.0.6+
Fix from $1,600 2021-05-28
Keycloak CRITICAL 9.6
CVE-2021-20195

A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …

Fix: 12.0.3+
Fix from $2,300 2021-05-28
MariaDB CRITICAL 9.0
CVE-2020-15180EPSS 6%

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be e…

Fix: 5.6.49 / 5.6.49-28.42.2+
Fix from $2,300 2021-05-27
S5700 Firmware HIGH 7.5
CVE-2021-22359

There is a denial of service vulnerability in the verisions V200R005C00SPC500 of S5700 and V200R005C00SPC500 of S6700. An attacker could exploit this…

Mitigation only
Fix from $1,950 2021-05-27
Enterprise Linux MEDIUM 5.5
CVE-2021-30501

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abor…

Patch available
Fix from $1,600 2021-05-27
Jakarta Expression Language MEDIUM 5.3
CVE-2021-28170

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated…

Fix: 2.3.0+
Fix from $1,600 2021-05-26