Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Libslic3r MEDIUM 6.5
CVE-2020-28590

An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92a…

No fix yet
Fix from $1,600 2021-04-13
Android MEDIUM 5.5
CVE-2021-0400

In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency se…

Patch available
Fix from $1,600 2021-04-13
Fedora MEDIUM 6.5
CVE-2021-21393

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.28.0+
Fix from $1,600 2021-04-12
Fedora MEDIUM 6.5
CVE-2021-21394

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.28.0+
Fix from $1,600 2021-04-12
Smartthings MEDIUM 5.3
CVE-2021-25378

Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.

Fix: 1.7.63.6+
Fix from $1,600 2021-04-09
Android HIGH 8.8
CVE-2021-25356

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a…

No fix yet
Fix from $1,950 2021-04-09
Channelmgnt HIGH 8.1
CVE-2021-21431

sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot usin…

Fix: 2.0.1+
Fix from $1,950 2021-04-09
Enterprise Linux MEDIUM 6.5
CVE-2021-3482

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetada…

Fix: after 0.27.3
Fix from $1,600 2021-04-08
Clamav HIGH 7.5
CVE-2021-1404

A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote att…

Mitigation only
Fix from $1,950 2021-04-08
Clamav HIGH 7.5
CVE-2021-1252

A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated…

Mitigation only
Fix from $1,950 2021-04-08
Catalyst Sd Wan Manager HIGH 7.8
CVE-2021-1480

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe…

Fix: 19.2.4 / 20.3.3+
Fix from $1,950 2021-04-08
Rv110w Firmware CRITICAL 9.8
CVE-2021-1459

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticate…

Mitigation only
Fix from $2,300 2021-04-08
Catalyst Sd Wan Manager HIGH 7.8
CVE-2021-1137

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe…

Fix: 19.2.4 / 20.3.3+
Fix from $1,950 2021-04-08
Csrb31024 Firmware HIGH 7.8
CVE-2020-11237

Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in Snapdragon Auto, Sn…

Mitigation only
Fix from $1,950 2021-04-07
Syncthing HIGH 7.5
CVE-2021-21404

Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and …

Fix: 1.15.0+
Fix from $1,950 2021-04-06
Umoci MEDIUM 5.5
CVE-2021-29136

Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal whe…

Fix: 0.4.7 / 3.7.3+
Fix from $1,600 2021-04-06
Wyse Thinos MEDIUM 6.3
CVE-2021-21532

Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redir…

Fix: 8.6+
Fix from $1,600 2021-04-02
Ipados HIGH 8.8
CVE-2021-1748

A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4. Processin…

Fix: 7.3 / 14.4+
Fix from $1,950 2021-04-02
Debian Linux MEDIUM 5.5
CVE-2020-10001

An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, …

Fix: 11.1.0+
Fix from $1,600 2021-04-02
Hostapd MEDIUM 5.3
CVE-2021-30004

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

Patch available
Fix from $1,600 2021-04-02
Exposure Notifications Verification Server HIGH 8.8
CVE-2021-22538

A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh…

Fix: 0.23.1+
Fix from $1,950 2021-03-31
Netmask MEDIUM 5.3
CVE-2021-29418

The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in …

Fix: 2.0.1+
Fix from $1,600 2021-03-30
Knot Resolver HIGH 7.5
CVE-2018-1110

A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.

Fix: 2.3.0+
Fix from $1,950 2021-03-30
Container Network Interface HIGH 7.2
CVE-2021-20206

An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'ty…

Fix: 0.8.1+
Fix from $1,950 2021-03-26
Nim HIGH 8.8
CVE-2021-21372

Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ…

Fix: 1.2.10 / 1.4.4+
Fix from $1,950 2021-03-26
Ios Xe MEDIUM 6.7
CVE-2021-1454

Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating s…

Mitigation only
Fix from $1,600 2021-03-24
Jabber HIGH 7.2
CVE-2021-1469

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execut…

Fix: 12.1.5 / 12.5.4+
Fix from $1,950 2021-03-24
Ios Xe HIGH 7.5
CVE-2021-1431

A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, r…

Mitigation only
Fix from $1,950 2021-03-24
Ios Xe HIGH 7.3
CVE-2021-1432

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyi…

Mitigation only
Fix from $1,950 2021-03-24
Ios Xe MEDIUM 6.7
CVE-2021-1383

Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating s…

No fix yet
Fix from $1,600 2021-03-24