Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Linux Kernel HIGH 7.8
CVE-2021-20194

There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CO…

Patch available
Fix from $1,950 2021-02-23
3scale Api Management MEDIUM 6.5
CVE-2021-20252

A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i…

Mitigation only
Fix from $1,600 2021-02-23
Debian Linux HIGH 7.4
CVE-2021-20247

A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or…

Fix: 1.3.5 / 1.4.1+
Fix from $1,950 2021-02-23
Acrobat MEDIUM 6.5
CVE-2020-29075EPSS 8%

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information…

Fix: after 20.013.20066
Fix from $1,600 2021-02-23
Apq8009 Firmware HIGH 7.8
CVE-2020-11204

Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are re…

Mitigation only
Fix from $1,950 2021-02-22
Aqt1000 Firmware HIGH 7.8
CVE-2020-11253

Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snap…

Mitigation only
Fix from $1,950 2021-02-22
Aqt1000 Firmware HIGH 7.8
CVE-2020-11194

Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdr…

Mitigation only
Fix from $1,950 2021-02-22
Apq8009 Firmware HIGH 7.8
CVE-2020-11195

Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffers in Snapdragon Au…

Mitigation only
Fix from $1,950 2021-02-22
Ethernet Network Adapter E810 Firmware MEDIUM 5.5
CVE-2020-24502

Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may…

Fix: 1.0.4 / 1.4.29.0+
Fix from $1,600 2021-02-17
C200 Firmware HIGH 8.0
CVE-2020-7848

The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attac…

Mitigation only
Fix from $1,950 2021-02-17
Curix HIGH 8.8
CVE-2020-7849

A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability …

Mitigation only
Fix from $1,950 2021-02-17
Graphics Drivers HIGH 7.8
CVE-2020-12385

Improper input validation in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable escalatio…

Fix: 26.20.100.8141+
Fix from $1,950 2021-02-17
Sgx Platform MEDIUM 5.5
CVE-2020-24452

Improper input validation in the Intel(R) SGX Platform Software for Windows* may allow an authenticated user to potentially enable a denial of servic…

Fix: 2.10.100.2+
Fix from $1,600 2021-02-17
Epid Software Development Kit HIGH 7.8
CVE-2020-24453

Improper input validation in the Intel(R) EPID SDK before version 8, may allow an authenticated user to potentially enable an escalation of privilege…

Fix: 8.0+
Fix from $1,950 2021-02-17
Graphics Drivers MEDIUM 5.5
CVE-2020-12363

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow …

Fix: 26.20.100.7212+
Fix from $1,600 2021-02-17
Graphics Drivers HIGH 7.8
CVE-2020-12366

Insufficient input validation in some Intel(R) Graphics Drivers before version 27.20.100.8587 may allow a privileged user to potentially enable an es…

Fix: 27.20.100.8587+
Fix from $1,950 2021-02-17
Bmc Firmware HIGH 7.8
CVE-2020-12377

Insufficient input validation in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a…

Fix: 2.47+
Fix from $1,950 2021-02-17
PHP MEDIUM 5.3
CVE-2020-7071

In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP …

Fix: 7.3.26 / 7.4.14+
Fix from $1,600 2021-02-15
Hg6245d Firmware HIGH 7.5
CVE-2021-27179EPSS 14%

An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c…

No fix yet
Fix from $1,950 2021-02-10
Inoerp CRITICAL 9.8
CVE-2020-28870

In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalizati…

No fix yet
Fix from $2,300 2021-02-10
Emc Powerscale Onefs HIGH 7.8
CVE-2020-26193

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI_PRIV_CLUSTER privilege may e…

Mitigation only
Fix from $1,950 2021-02-09
Pyyaml CRITICAL 9.8
CVE-2020-14343EPSS 6%

A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes un…

Fix: 5.4+
Fix from $2,300 2021-02-09
Owncloud CRITICAL 9.1
CVE-2020-28645

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the…

Fix: 10.6.0+
Fix from $2,300 2021-02-09
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4790

IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperly validating a supplied URL, …

Patch available
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21126EPSS 9%

Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21123EPSS 10%

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions vi…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Max Spyware Detector HIGH 7.8
CVE-2020-12122

In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of service (BSOD) or possibly have…

No fix yet
Fix from $1,950 2021-02-05
Android MEDIUM 6.7
CVE-2021-0345

In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,600 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1315

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1316

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04