Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Notes HIGH 7.5
CVE-2020-14258

HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker…

Patch available
Fix from $1,950 2020-11-21
Wf2429tb Firmware MEDIUM 6.6
CVE-2020-7842

Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection and execution when the time set…

Mitigation only
Fix from $1,600 2020-11-20
Webex Meetings MEDIUM 5.3
CVE-2020-3441

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information…

Fix: 3.0+
Fix from $1,600 2020-11-18
Enterprise Nfv Infrastructure Software CRITICAL 9.8
CVE-2020-3470

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to exec…

Fix: 3.2.11.3 / 4.4.1+
Fix from $2,300 2020-11-18
Webex Meetings Server MEDIUM 6.5
CVE-2020-3471

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional aud…

Fix: 3.0+
Fix from $1,600 2020-11-18
Xplatform HIGH 8.8
CVE-2020-7841

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun…

Fix: 9.2.2.250+
Fix from $1,950 2020-11-17
Security Manager CRITICAL 9.8
CVE-2020-27131EPSS 88%

Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker …

Fix: after 4.22
Fix from $2,300 2020-11-17
Security Manager CRITICAL 9.8
CVE-2020-27125

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The …

Fix: after 4.21
Fix from $2,300 2020-11-17
Nagios Xi HIGH 8.8
CVE-2020-28648EPSS 6%

Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.

Fix: 5.7.5+
Fix from $1,950 2020-11-16
Nio 50 Firmware HIGH 7.5
CVE-2020-25151

The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all versions).

No fix yet
Fix from $1,950 2020-11-13
Nip6300 Firmware MEDIUM 6.7
CVE-2020-9127

Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some ma…

Mitigation only
Fix from $1,600 2020-11-13
Data Center Manager MEDIUM 6.5
CVE-2020-8669

Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable info…

Fix: 3.6.2+
Fix from $1,600 2020-11-12
Data Center Manager HIGH 8.8
CVE-2020-12347

Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable esca…

Fix: 3.6.2+
Fix from $1,950 2020-11-12
Data Center Manager MEDIUM 6.5
CVE-2020-12349

Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable info…

Fix: 3.6.2+
Fix from $1,600 2020-11-12
Adas Ie MEDIUM 6.7
CVE-2020-12323

Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of priv…

Fix: 1.0.766+
Fix from $1,600 2020-11-12
Server Board S2600st Firmware MEDIUM 6.7
CVE-2020-0572

Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable es…

Fix: 02.01.0011 / 02.01.0012+
Fix from $1,600 2020-11-12
Converged Security And Manageability Engine MEDIUM 6.7
CVE-2020-8756

Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user…

Fix: 11.8.80 / 11.12.80+
Fix from $1,600 2020-11-12
Sugarcrm CRITICAL 9.8
CVE-2020-7472

An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9…

Fix: 8.0.7 / 9.0.4+
Fix from $2,300 2020-11-12
Proset\/wireless Wifi MEDIUM 6.5
CVE-2020-12314

Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enabl…

Fix: 21.110+
Fix from $1,600 2020-11-12
Dual Band Wireless Ac 3168 Firmware MEDIUM 6.5
CVE-2020-12322

Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enab…

Fix: 21.110+
Fix from $1,600 2020-11-12
Xeon Bronze 3206r Firmware HIGH 7.8
CVE-2020-0590

Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege…

Patch available
Fix from $1,950 2020-11-12
Qcm6125 Firmware HIGH 7.8
CVE-2020-11201

Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapd…

No fix yet
Fix from $1,950 2020-11-12
Pan Os HIGH 7.2
CVE-2020-2000

An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup…

Fix: 8.1.16 / 9.0.10+
Fix from $1,950 2020-11-12
Accountsservice MEDIUM 5.5
CVE-2020-16127

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read …

Fix: 0.6.55+
Fix from $1,600 2020-11-11
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-26817

SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing …

Mitigation only
Fix from $1,950 2020-11-10
Android HIGH 7.5
CVE-2020-0442

In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote de…

Patch available
Fix from $1,950 2020-11-10
Json8 Merge Patch HIGH 7.5
CVE-2020-8268

Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the glob…

Fix: 1.0.3+
Fix from $1,950 2020-11-09
Network Server MEDIUM 6.5
CVE-2020-28349

An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malfo…

Patch available
Fix from $1,600 2020-11-09
Ios Xe HIGH 7.5
CVE-2020-3444

A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic…

Fix: after 17.2.1
Fix from $1,950 2020-11-06
Anyconnect Secure Mobility Client HIGH 7.3
CVE-2020-3556

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, loc…

Mitigation only
Fix from $1,950 2020-11-06