Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Secure Firewall Threat Defense HIGH 7.5
CVE-2020-3317

A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to c…

Fix: 6.4.0.10 / 6.5.0.5+
Fix from $1,950 2020-10-21
Netweaver Compare Systems MEDIUM 6.5
CVE-2020-6366

SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administra…

Mitigation only
Fix from $1,600 2020-10-20
Object Path CRITICAL 9.8
CVE-2020-15256

A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `incl…

Fix: 0.11.5+
Fix from $2,300 2020-10-19
Fedora HIGH 7.5
CVE-2020-24388

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field o…

Fix: after 2.0.2
Fix from $1,950 2020-10-19
Sprecon E MEDIUM 6.7
CVE-2020-11496

Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks …

Fix: 8.64b+
Fix from $1,600 2020-10-19
Intelligent Management Center CRITICAL 9.8
CVE-2020-24649

A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)…

Fix: 7.3+
Fix from $2,300 2020-10-19
Intelligent Management Center CRITICAL 9.8
CVE-2020-24647

A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s…

Fix: 7.3+
Fix from $2,300 2020-10-19
Windows 10 HIGH 7.8
CVE-2020-1167

<p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully …

Patch available
Fix from $1,950 2020-10-16
Windows 10 HIGH 7.8
CVE-2020-16968

<p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully…

Patch available
Fix from $1,950 2020-10-16
Windows 10 HIGH 8.8
CVE-2020-16891

<p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on …

Patch available
Fix from $1,950 2020-10-16
Junos HIGH 7.5
CVE-2020-1672

On Juniper Networks Junos OS devices configured with DHCPv6 relay enabled, receipt of a specific DHCPv6 packet might crash the jdhcpd daemon. The jdh…

Mitigation only
Fix from $1,950 2020-10-16
Mist Cloud Ui HIGH 7.2
CVE-2020-1676

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a v…

Fix: 2020-09-02+
Fix from $1,950 2020-10-16
Mist Cloud Ui HIGH 7.2
CVE-2020-1677

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote atta…

Fix: 2020-09-02+
Fix from $1,950 2020-10-16
Junos HIGH 7.5
CVE-2020-1679

On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet…

Mitigation only
Fix from $1,950 2020-10-16
Junos MEDIUM 5.5
CVE-2020-1682

An input validation vulnerability exists in Juniper Networks Junos OS, allowing an attacker to crash the srxpfe process, causing a Denial of Service …

Mitigation only
Fix from $1,600 2020-10-16
Junos HIGH 8.8
CVE-2020-1656

The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vu…

Mitigation only
Fix from $1,950 2020-10-16
Junos HIGH 7.5
CVE-2020-1662

On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routing process daemon (RPD) crash and restart, limitin…

Mitigation only
Fix from $1,950 2020-10-16
Ipados HIGH 7.5
CVE-2020-9931

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may cause …

Fix: 13.6+
Fix from $1,950 2020-10-16
Ipados HIGH 7.5
CVE-2020-9914

An input validation issue existed in Bluetooth. This issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 1…

Fix: 13.4.8 / 13.6+
Fix from $1,950 2020-10-16
Ipados HIGH 8.8
CVE-2020-9870

A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attack…

Fix: 10.15.6 / 13.4.8+
Fix from $1,950 2020-10-16
Wire HIGH 8.0
CVE-2020-15258

In Wire before 3.20.x, `shell.openExternal` was used without checking the URL. This vulnerability allows an attacker to execute code on the victims m…

Fix: 3.20.2934+
Fix from $1,950 2020-10-16
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6372

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6373

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6374

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which …

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6375

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted …

Mitigation only
Fix from $1,600 2020-10-15
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6376

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources wh…

Mitigation only
Fix from $1,600 2020-10-15
Cloud Networking Operating System CRITICAL 9.8
CVE-2020-8349

An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ option…

Fix: 10.10.6.0+
Fix from $2,300 2020-10-14
Unified Endpoint Manager MEDIUM 5.5
CVE-2020-6933

An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and ear…

Fix: after 12.11.1
Fix from $1,600 2020-10-14
Hirouter Cd30 10 Firmware MEDIUM 6.5
CVE-2020-9122

Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in the LAN to cause service abno…

Fix: 10.0.2.37 / 10.0.3.33+
Fix from $1,600 2020-10-12
Curam Social Program Management MEDIUM 6.5
CVE-2020-4781

An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could resul…

Mitigation only
Fix from $1,600 2020-10-12