Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Dsr 150 Firmware HIGH 8.8
CVE-2020-25757

A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command API…

Fix: after 3.17
Fix from $1,950 2020-12-15
Dsr 150 Firmware HIGH 8.8
CVE-2020-25759

An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticat…

Fix: after 3.17
Fix from $1,950 2020-12-15
H0 Ecom100 Firmware HIGH 7.5
CVE-2020-25195

The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving…

Fix: after 5.0.1043
Fix from $1,950 2020-12-15
Android MEDIUM 6.5
CVE-2020-27029

In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-12-15
Android MEDIUM 5.5
CVE-2020-0493

In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to loca…

Mitigation only
Fix from $1,600 2020-12-15
Picotcp HIGH 7.5
CVE-2020-17444

An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid…

Fix: after 1.7.0
Fix from $1,950 2020-12-11
Uip HIGH 8.3
CVE-2020-17439

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the i…

Mitigation only
Fix from $1,950 2020-12-11
Fabric Operating System MEDIUM 6.7
CVE-2020-15375

Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the comman…

Fix: 7.4.2g / 8.1.2k+
Fix from $1,600 2020-12-11
Resilient Security Orchestration Automation And Response HIGH 8.8
CVE-2020-4633

IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input val…

Mitigation only
Fix from $1,950 2020-12-11
Fedora HIGH 7.8
CVE-2020-27828

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-b…

Fix: 2.0.23+
Fix from $1,950 2020-12-11
GitLab MEDIUM 6.5
CVE-2020-26409

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource b…

Fix: 13.4.7 / 13.5.5+
Fix from $1,600 2020-12-11
Anydesk HIGH 7.8
CVE-2020-27614

AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local…

Fix: after 6.0.2
Fix from $1,950 2020-12-09
Ipados MEDIUM 5.5
CVE-2020-9977

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue …

Fix: 11.0.1 / 14.2+
Fix from $1,600 2020-12-08
Ec Cube HIGH 7.5
CVE-2020-5680

Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) conditio…

Fix: after 3.0.18
Fix from $1,950 2020-12-03
Manageone HIGH 7.2
CVE-2020-9115

ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An …

Mitigation only
Fix from $1,950 2020-12-01
R00cpu Firmware HIGH 7.5
CVE-2020-16850

Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over…

Fix: after 52
Fix from $1,950 2020-11-30
Factorytalk Linx HIGH 7.5
CVE-2020-27253

A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticat…

Fix: after 6.11
Fix from $1,950 2020-11-26
Nanopb HIGH 7.5
CVE-2020-26243

Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can le…

Fix: 0.3.9.7 / 0.4.4+
Fix from $1,950 2020-11-25
Unomi CRITICAL 9.8
CVE-2020-13942EPSS 68%

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…

Fix: 1.5.2+
Fix from $2,300 2020-11-24
Fedora HIGH 7.5
CVE-2020-26890

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing re…

Fix: 1.20.0+
Fix from $1,950 2020-11-24
Jingyun Antivirus HIGH 7.8
CVE-2018-16719

In Jingyun Antivirus v2.4.2.39, the driver file (hookbody.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified ot…

No fix yet
Fix from $1,950 2020-11-23
Jingyun Antivirus HIGH 7.8
CVE-2018-16720

In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o…

No fix yet
Fix from $1,950 2020-11-23
Jingyun Antivirus HIGH 7.8
CVE-2018-16721

In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o…

No fix yet
Fix from $1,950 2020-11-23
Jingyun Antivirus HIGH 7.8
CVE-2018-16722

In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o…

No fix yet
Fix from $1,950 2020-11-23
Jingyun Antivirus HIGH 7.8
CVE-2018-16723

In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o…

No fix yet
Fix from $1,950 2020-11-23
Linux Kernel HIGH 8.8
CVE-2020-12351EPSS 8%

Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

Fix: 4.9.240 / 4.14.202+
Fix from $1,950 2020-11-23
MongoDB MEDIUM 6.5
CVE-2018-20804

A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects Mon…

Fix: 3.6.13 / 4.0.10+
Fix from $1,600 2020-11-23
MongoDB HIGH 7.5
CVE-2020-7925

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a spec…

Fix: 4.2.9+
Fix from $1,950 2020-11-23
Domino HIGH 7.5
CVE-2020-14230

HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacke…

Fix: 9.0.1 / 10.0.1+
Fix from $1,950 2020-11-21
Domino HIGH 7.5
CVE-2020-14234

HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the …

Fix: 9.0.1 / 10.0.1+
Fix from $1,950 2020-11-21