Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Taurus An00b Firmware MEDIUM 6.7
CVE-2020-9105

Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is …

Fix: 10.1.0.156+
Fix from $1,600 2020-10-09
Industrial Network Director MEDIUM 6.5
CVE-2020-3567

A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU …

Fix: 1.9.0+
Fix from $1,600 2020-10-08
Asyncos MEDIUM 5.8
CVE-2020-3568

A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat…

Fix: after 13.5.2
Fix from $1,600 2020-10-08
Staros MEDIUM 6.7
CVE-2020-3601

A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate…

Fix: 21.19.n4+
Fix from $1,600 2020-10-08
Staros MEDIUM 6.7
CVE-2020-3602

A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate…

Fix: 21.19.n4+
Fix from $1,600 2020-10-08
Contao MEDIUM 5.3
CVE-2020-25768

Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end …

Fix: 4.4.52 / 4.9.6+
Fix from $1,600 2020-10-07
Android HIGH 7.5
CVE-2020-26597

An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect input validation, leading to a cr…

Mitigation only
Fix from $1,950 2020-10-06
Node Pdf Generator HIGH 8.2
CVE-2020-7740

This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-…

Mitigation only
Fix from $1,950 2020-10-06
Socket.io File HIGH 7.8
CVE-2020-24807

The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitr…

Fix: after 2.0.31
Fix from $1,950 2020-10-06
Electron HIGH 7.5
CVE-2020-15174

In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent navigations to unexpected destin…

Fix: 8.5.1 / 9.3.0+
Fix from $1,950 2020-10-06
Linux Kernel HIGH 7.2
CVE-2020-25643

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper i…

Fix: 4.4.238 / 4.9.238+
Fix from $1,950 2020-10-06
Virtual Gpu Manager HIGH 7.1
CVE-2020-5985

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering o…

Fix: 8.5 / 10.4+
Fix from $1,950 2020-10-02
Virtual Gpu Manager MEDIUM 5.5
CVE-2020-5986

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or …

Fix: 8.5 / 10.4+
Fix from $1,600 2020-10-02
PHP MEDIUM 6.5
CVE-2020-7069

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 byte…

Fix: 5.19.0 / 7.2.34+
Fix from $1,600 2020-10-02
PHP MEDIUM 5.3
CVE-2020-7070EPSS 5%

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names a…

Fix: 5.19.0 / 7.2.34+
Fix from $1,600 2020-10-02
Toolkit MEDIUM 5.0
CVE-2020-15228

In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by ge…

Fix: 1.2.6+
Fix from $1,600 2020-10-01
Ceph Storage MEDIUM 6.1
CVE-2020-25626

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails…

Fix: 3.12.0+
Fix from $1,600 2020-09-30
Security Verify Privilege Vault Remote On Premises HIGH 7.8
CVE-2020-4607

IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper…

Patch available
Fix from $1,950 2020-09-29
Tensorflow MEDIUM 6.5
CVE-2020-15210

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15199

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` does not validate that the input arguments form a valid ragged tensor. In particula…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15200

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tenso…

Patch available
Fix from $1,600 2020-09-25
Tensorflow HIGH 7.5
CVE-2020-15203

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker…

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow HIGH 7.5
CVE-2020-15206

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of …

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15190

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outp…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15191

In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variabl…

Patch available
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.3
CVE-2020-15194

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the sh…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 6.3
CVE-2020-15197

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Patch available
Fix from $1,600 2020-09-25
Micloud Management Portal HIGH 7.2
CVE-2020-24593

Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to imp…

Fix: after 6.0
Fix from $1,950 2020-09-25
Pexip Infinity MEDIUM 5.3
CVE-2020-24615

Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.

Fix: 24.1+
Fix from $1,600 2020-09-25
Micontact Center Business HIGH 7.1
CVE-2020-24692

The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input va…

Fix: 9.3.0.0+
Fix from $1,950 2020-09-25