Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Openshift Container Platform MEDIUM 5.5
CVE-2021-20297

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat …

Fix: 1.30.0+
Fix from $1,600 2021-05-26
Modicon M241 Firmware HIGH 7.5
CVE-2021-22699

Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service w…

Fix: 5.1.9.1+
Fix from $1,950 2021-05-26
Vcenter Server CRITICAL 9.8
CVE-2021-21985 KEVEPSS 100%

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in whi…

Fix: 3.10.2.1 / 4.2.1+
Fix from $2,300 2021-05-26
Zephyr MEDIUM 5.5
CVE-2020-13602

Remote Denial of Service in LwM2M do_write_op_tlv. Zephyr versions >= 1.14.2, >= 2.2.0 contain Improper Input Validation (CWE-20), Loop with Unreacha…

Fix: after 2.2.0
Fix from $1,600 2021-05-25
Enterprise Linux HIGH 7.5
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th…

Fix: 1.0.1+
Fix from $1,950 2021-05-21
Ceph MEDIUM 5.3
CVE-2021-3531

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes…

Fix: 14.2.21+
Fix from $1,600 2021-05-18
Ceph MEDIUM 6.5
CVE-2021-3524

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection …

Fix: 14.2.21+
Fix from $1,600 2021-05-17
Openshift Container Platform HIGH 7.1
CVE-2020-27833

A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c…

Fix: after 4.7
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29611

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Mercedes Benz User Experience MEDIUM 6.8
CVE-2021-23906

An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked …

Fix: after 2021
Fix from $1,600 2021-05-13
Fedora MEDIUM 6.5
CVE-2020-25713

A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.

Patch available
Fix from $1,600 2021-05-13
Fedora HIGH 7.8
CVE-2020-27823

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. T…

Fix: 2.4.0+
Fix from $1,950 2021-05-13
Ipc Diagnostics Ua Server MEDIUM 5.3
CVE-2020-12526

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are v…

Fix: after 3.3.18
Fix from $1,600 2021-05-13
Enterprise Linux MEDIUM 5.5
CVE-2020-27824

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input t…

Fix: 2.4.0+
Fix from $1,600 2021-05-13
Unified Endpoint Management MEDIUM 5.5
CVE-2021-22152

A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and e…

Fix: after 12.12.0
Fix from $1,600 2021-05-13
Awus036h Firmware MEDIUM 6.5
CVE-2020-26143

An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plai…

Mitigation only
Fix from $1,600 2021-05-11
Galaxy I9305 Firmware MEDIUM 6.5
CVE-2020-26144

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long…

Fix: 10.0.1-31 / 11.0.0-36+
Fix from $1,600 2021-05-11
Galaxy I9305 Firmware MEDIUM 6.5
CVE-2020-26145

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcas…

Fix: 1.2+
Fix from $1,600 2021-05-11
Galaxy I9305 Firmware MEDIUM 5.3
CVE-2020-26146EPSS 6%

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive p…

Fix: 10.0.1-31 / 11.0.0-36+
Fix from $1,600 2021-05-11
Exchange Server HIGH 7.8
CVE-2021-31198

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
Universal Turing Machine HIGH 7.8
CVE-2021-32471

Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code…

No fix yet
Fix from $1,950 2021-05-10
Apq8009 HIGH 7.5
CVE-2020-11268

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdr…

Mitigation only
Fix from $1,950 2021-05-07
Catalyst Sd Wan Manager CRITICAL 9.8
CVE-2021-1468

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $2,300 2021-05-06
Catalyst Sd Wan Manager HIGH 8.8
CVE-2021-1505

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 7.2
CVE-2021-1506

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 8.8
CVE-2021-1508

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 19.2.99 / 20.3.3+
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 7.5
CVE-2021-1513

A vulnerability in the vDaemon process of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resultin…

Fix: 20.3.1 / 20.4.1+
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 7.8
CVE-2021-1514

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Adm…

Fix: 18.3 / 20.1.1+
Fix from $1,950 2021-05-06
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2021-1519

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, loc…

Fix: 4.10.00093+
Fix from $1,600 2021-05-06
Catalyst Sd Wan Manager HIGH 7.5
CVE-2021-1275

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $1,950 2021-05-06