Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Control For Beaglebone Sl HIGH 7.3
CVE-2021-29242

CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's…

Fix: 4.1.0.0+
Fix from $1,950 2021-05-03
Cumulative Distribution Function HIGH 7.5
CVE-2021-29486

cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution function from data array of …

Fix: 2.0.0+
Fix from $1,950 2021-04-30
MongoDB MEDIUM 6.5
CVE-2021-20326

A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior …

Fix: 4.4.4+
Fix from $1,600 2021-04-30
Git HIGH 8.8
CVE-2021-29468

Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that contains symbolic links as we…

Fix: after 2.31.1-1
Fix from $1,950 2021-04-29
Virtual Gpu Manager HIGH 7.8
CVE-2021-1084

NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not va…

Fix: 11.4 / 12.2+
Fix from $1,950 2021-04-29
Virtual Gpu Manager HIGH 7.3
CVE-2021-1085

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to write to a shared memory locati…

Fix: 8.7 / 11.4+
Fix from $1,950 2021-04-29
Virtual Gpu Manager HIGH 7.8
CVE-2021-1080

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which certain input data is not validated, which may lead …

Fix: 8.7 / 11.4+
Fix from $1,950 2021-04-29
Secure Firewall Threat Defense HIGH 7.8
CVE-2021-1448

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary command…

Fix: 6.4.0.10 / 6.5.0.5+
Fix from $1,950 2021-04-29
Systeminformation CRITICAL 9.8
CVE-2021-21388

systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions …

Fix: 5.6.4+
Fix from $2,300 2021-04-29
Secure Firewall Threat Defense HIGH 8.6
CVE-2021-1402

A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote…

Fix: 6.4.0 / 6.6.0+
Fix from $1,950 2021-04-29
Debian Linux HIGH 7.5
CVE-2021-31863

Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine us…

Fix: 4.0.9 / 4.1.3+
Fix from $1,950 2021-04-28
Spectrum Scale MEDIUM 6.0
CVE-2020-4981

IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 1…

Fix: after 5.1.0.3
Fix from $1,600 2021-04-27
Hedgedoc MEDIUM 5.8
CVE-2021-29474

HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's fil…

Fix: 1.8.0+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21208

Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain s…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21221

Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer …

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Cscape HIGH 7.8
CVE-2021-22678

Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruptio…

Fix: 9.90+
Fix from $1,950 2021-04-23
Junos MEDIUM 6.5
CVE-2021-0267

An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an atta…

Mitigation only
Fix from $1,600 2021-04-22
Junos MEDIUM 6.5
CVE-2021-0214

A vulnerability in the distributed or centralized periodic packet management daemon (PPMD) of Juniper Networks Junos OS may cause receipt of a malfor…

Mitigation only
Fix from $1,600 2021-04-22
Mediawiki HIGH 7.5
CVE-2021-31555

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka oauth_registered_consumer.oarc…

Fix: after 1.35.2
Fix from $1,950 2021-04-22
Pupnp CRITICAL 9.8
CVE-2021-29462

The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears…

Fix: 1.14.6+
Fix from $2,300 2021-04-20
Xplatform CRITICAL 9.8
CVE-2020-7857

A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient vali…

Fix: 9.2.2.280+
Fix from $2,300 2021-04-20
Globalprotect MEDIUM 5.5
CVE-2021-3038

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically…

Fix: 5.1.8 / 5.2.4+
Fix from $1,600 2021-04-20
Qts CRITICAL 9.8
CVE-2020-36195

An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulne…

Fix: 1.3.4 / 4.3.3+
Fix from $2,300 2021-04-17
Sydent HIGH 7.5
CVE-2021-29430

Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a…

Fix: 2.3.0+
Fix from $1,950 2021-04-15
Sydent MEDIUM 6.5
CVE-2021-29431

Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validatio…

Fix: 2.3.0+
Fix from $1,600 2021-04-15
Sydent MEDIUM 5.7
CVE-2021-29432

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This co…

Fix: 2.3.0+
Fix from $1,600 2021-04-15
Resourcexpress MEDIUM 5.3
CVE-2020-28898

In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execut…

Fix: after 4.9k
Fix from $1,600 2021-04-15
Windows 10 HIGH 7.8
CVE-2021-26415

Windows Installer Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-04-13
Intelligent Power Manager CRITICAL 9.6
CVE-2021-23278

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input …

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Intelligent Power Manager CRITICAL 10.0
CVE-2021-23279EPSS 27%

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper inpu…

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13