Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Exponent Cms CRITICAL 9.8
CVE-2016-9021

Exponent CMS before 2.6.0 has improper input validation in storeController.php.

Fix: 2.6.0+
Fix from $2,300 2020-12-31
Exponent Cms CRITICAL 9.8
CVE-2016-9022

Exponent CMS before 2.6.0 has improper input validation in usersController.php.

Fix: 2.6.0+
Fix from $2,300 2020-12-31
Exponent Cms CRITICAL 9.8
CVE-2016-9023

Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.

Fix: 2.6.0+
Fix from $2,300 2020-12-31
Exponent Cms CRITICAL 9.8
CVE-2016-9025

Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.

Fix: 2.6.0+
Fix from $2,300 2020-12-31
Exponent Cms CRITICAL 9.8
CVE-2016-9026

Exponent CMS before 2.6.0 has improper input validation in fileController.php.

Fix: 2.6.0+
Fix from $2,300 2020-12-31
Uri.js MEDIUM 6.5
CVE-2020-26291

URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`…

Fix: 1.19.4+
Fix from $1,600 2020-12-31
Nms300 Firmware HIGH 8.8
CVE-2020-35789

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

Fix: 1.6.0.27+
Fix from $1,950 2020-12-30
Joomla\! HIGH 7.5
CVE-2020-35616EPSS 6%

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

Fix: after 3.9.22
Fix from $1,950 2020-12-28
Domino HIGH 7.5
CVE-2020-14273

HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated at…

No fix yet
Fix from $1,950 2020-12-28
Cloudengine 12800 Firmware MEDIUM 6.7
CVE-2020-9137

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to in…

Mitigation only
Fix from $1,600 2020-12-24
Qes HIGH 7.5
CVE-2020-2504

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues…

Fix: 2.1.1+
Fix from $1,950 2020-12-24
Ipv6 HIGH 7.1
CVE-2020-27338

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows an unauthenticated remote atta…

Fix: 6.0.1.68+
Fix from $1,950 2020-12-22
Symphony \+ Historian CRITICAL 9.8
CVE-2020-24679

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even ex…

Mitigation only
Fix from $2,300 2020-12-22
Ipv6 MEDIUM 5.3
CVE-2020-27336

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthentica…

Fix: 6.0.1.68+
Fix from $1,600 2020-12-22
Ipv6 HIGH 7.3
CVE-2020-27337

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to c…

Fix: 6.0.1.68+
Fix from $1,950 2020-12-22
Hcl Client Application Access HIGH 8.8
CVE-2020-14231

A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resul…

Mitigation only
Fix from $1,950 2020-12-22
Odoo HIGH 8.8
CVE-2019-11781

Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to tri…

Fix: after 12.0
Fix from $1,950 2020-12-22
Odoo CRITICAL 9.1
CVE-2018-15632

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers…

Fix: after 11.0
Fix from $2,300 2020-12-22
Mediawiki HIGH 7.5
CVE-2020-35623

An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation wit…

Fix: after 1.35.1
Fix from $1,950 2020-12-21
Workstation MEDIUM 6.5
CVE-2020-3999

VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 an…

Fix: 11.5.7 / 15.5.7+
Fix from $1,600 2020-12-21
Thingsboard HIGH 8.8
CVE-2020-27687

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-…

Fix: 3.2+
Fix from $1,950 2020-12-18
Micollab MEDIUM 6.1
CVE-2020-25606

The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input val…

Fix: 9.2+
Fix from $1,600 2020-12-18
Micollab HIGH 7.2
CVE-2020-25608

The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.

Fix: 9.2+
Fix from $1,950 2020-12-18
Micollab MEDIUM 6.1
CVE-2020-25611

The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to imprope…

Fix: 9.2+
Fix from $1,600 2020-12-18
Businesscti Enterprise HIGH 8.8
CVE-2020-27154

The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access …

Fix: 6.4.11 / 7.0.3+
Fix from $1,950 2020-12-18
Stove HIGH 8.8
CVE-2020-7838

A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrar…

Fix: after 0.0.4.71
Fix from $1,950 2020-12-18
Plcnext Firmware MEDIUM 6.5
CVE-2020-12521

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET …

Fix: 2021.0+
Fix from $1,600 2020-12-17
Hypervisor Introspection MEDIUM 5.5
CVE-2020-15292

Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTa…

Fix: 1.132.2+
Fix from $1,600 2020-12-17
Hypervisor Introspection MEDIUM 5.5
CVE-2020-15293

Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input va…

Mitigation only
Fix from $1,600 2020-12-17
Growi HIGH 7.5
CVE-2020-5682

Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and ear…

Fix: 4.1.12 / 4.2.3+
Fix from $1,950 2020-12-16