Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unity Connection MEDIUM 6.5
CVE-2020-3130

A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the unde…

Fix: 11.5su7 / 12.5su2+
Fix from $1,600 2020-09-23
Email Security Appliance HIGH 7.5
CVE-2020-3133

A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remo…

Fix: 13.0+
Fix from $1,950 2020-09-23
Email Security Appliance HIGH 8.6
CVE-2019-1947

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthentica…

Mitigation only
Fix from $1,950 2020-09-23
Content Security Management Appliance MEDIUM 5.3
CVE-2019-1983

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security …

Fix: 11.0.1-161 / 11.0.3-251+
Fix from $1,600 2020-09-23
Webex Meetings Online MEDIUM 5.5
CVE-2020-3116

A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of …

Mitigation only
Fix from $1,600 2020-09-23
Managed Services Accelerator MEDIUM 6.1
CVE-2019-15974

A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user t…

Fix: 3.7.0+
Fix from $1,600 2020-09-23
Unified Customer Voice Portal MEDIUM 6.8
CVE-2019-16017

A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP…

Fix: 11.6 / 12.0+
Fix from $1,600 2020-09-23
Roomos HIGH 7.5
CVE-2019-15289

Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthentica…

Fix: 9.8.0+
Fix from $1,950 2020-09-23
Rv016 Multi Wan Vpn Firmware HIGH 7.2
CVE-2019-15957

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…

Fix: 1.5.1.05 / 4.2.3.10+
Fix from $1,950 2020-09-23
Spa500 Series Ip Phones Firmware MEDIUM 6.6
CVE-2019-15959

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the devi…

Fix: after 7.5.7
Fix from $1,600 2020-09-23
Chrome MEDIUM 6.5
CVE-2020-6567

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to by…

Fix: 85.0.4183.83+
Fix from $1,600 2020-09-21
Chrome HIGH 8.8
CVE-2020-15964

Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a …

Fix: 85.0.4183.121+
Fix from $1,950 2020-09-21
Tiny Tiny Rss CRITICAL 9.8
CVE-2020-25787EPSS 18%

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.

Fix: 2020-09-16+
Fix from $2,300 2020-09-19
Reset Password CRITICAL 9.8
CVE-2020-15181

The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the sy…

Fix: 1.2.0+
Fix from $2,300 2020-09-18
Android MEDIUM 6.5
CVE-2020-0362

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0363

In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional…

Mitigation only
Fix from $1,600 2020-09-17
Android CRITICAL 9.8
CVE-2020-0333

In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges…

Mitigation only
Fix from $2,300 2020-09-17
Android MEDIUM 6.5
CVE-2020-0351

In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0353

In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0320

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0287

In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0301

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0130

In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system pr…

Mitigation only
Fix from $1,950 2020-09-17
Xerces MEDIUM 5.3
CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforce…

Fix: 2.12.0+
Fix from $1,600 2020-09-17
Freebox Hd Firmware CRITICAL 9.6
CVE-2020-24374

A DNS rebinding vulnerability in Freebox v5 before 1.5.29.

Fix: 1.5.29+
Fix from $2,300 2020-09-16
Freebox Revolution Firmware CRITICAL 9.6
CVE-2020-24376

A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.

Fix: 4.2.3+
Fix from $2,300 2020-09-16
Freebox Revolution Firmware CRITICAL 9.6
CVE-2020-24377

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.

Fix: 4.2.3+
Fix from $2,300 2020-09-16
Codemeter HIGH 7.5
CVE-2020-14513

CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified len…

Fix: 6.81+
Fix from $1,950 2020-09-16
Xmlquery CRITICAL 9.8
CVE-2020-25614

xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV…

Fix: 1.3.1+
Fix from $2,300 2020-09-16
Windows 10 MEDIUM 6.5
CVE-2020-0904

<p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on…

Patch available
Fix from $1,600 2020-09-11