Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Esp Idf MEDIUM 6.5
CVE-2020-13594

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the chan…

Fix: after 4.2
Fix from $1,600 2020-08-31
Spectrum Protect HIGH 7.5
CVE-2020-4559

IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force …

Fix: after 8.1.10.000
Fix from $1,950 2020-08-28
Nx Os HIGH 8.6
CVE-2020-3397

A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2020-08-27
Nx Os HIGH 8.6
CVE-2020-3398

A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2020-08-27
Nx Os HIGH 7.2
CVE-2020-3454

A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that coul…

Mitigation only
Fix from $1,950 2020-08-27
Sg200 50 Firmware MEDIUM 5.3
CVE-2020-3496

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attack…

Fix: after 2.5.5.47
Fix from $1,600 2020-08-26
8000p Ip Camera Firmware HIGH 8.8
CVE-2020-3506

Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenti…

Mitigation only
Fix from $1,950 2020-08-26
8000p Ip Camera Firmware HIGH 8.8
CVE-2020-3507

Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenti…

Mitigation only
Fix from $1,950 2020-08-26
Data Center Network Manager HIGH 8.1
CVE-2020-3519

A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to c…

Fix: 11.4+
Fix from $1,950 2020-08-26
Data Center Network Manager MEDIUM 6.5
CVE-2020-3521

A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct …

Fix: 11.4+
Fix from $1,600 2020-08-26
Ansible HIGH 7.3
CVE-2019-14904

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name…

Fix: 2.7.15 / 2.8.7+
Fix from $1,950 2020-08-26
Parallels Desktop MEDIUM 6.5
CVE-2020-17393

This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first…

Fix: 15.1.4+
Fix from $1,600 2020-08-25
Vault Ssh Helper HIGH 7.5
CVE-2020-24359

HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network inte…

Fix: 0.2.0+
Fix from $1,950 2020-08-20
Robot Operating System HIGH 8.8
CVE-2020-10289

Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whene…

Patch available
Fix from $1,950 2020-08-20
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2020-3434

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, …

Fix: after 4.9.00086
Fix from $1,600 2020-08-17
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2020-3435

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, …

Fix: after 4.9.00086
Fix from $1,600 2020-08-17
Sg250x 24 Firmware HIGH 8.6
CVE-2020-3363

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attack…

Mitigation only
Fix from $1,950 2020-08-17
Solr HIGH 8.8
CVE-2020-13941

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org…

Fix: 8.6.0+
Fix from $1,950 2020-08-17
Nim HIGH 7.5
CVE-2020-15694

In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not …

Fix: after 1.2.6
Fix from $1,950 2020-08-14
Raid Web Console 3 HIGH 7.5
CVE-2020-8688

Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service v…

Fix: 7.012.016.000+
Fix from $1,950 2020-08-13
Ax201 Firmware HIGH 7.8
CVE-2020-0555

Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privil…

Patch available
Fix from $1,950 2020-08-13
S2600stqr Firmware HIGH 8.2
CVE-2020-12299

Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially…

Fix: 02.01.0012+
Fix from $1,950 2020-08-13
Nuc8i7behga Firmware MEDIUM 6.7
CVE-2020-8742

Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local acces…

Patch available
Fix from $1,600 2020-08-13
Server Board S2600wt Firmware MEDIUM 5.5
CVE-2020-8717

Improper input validation in a subsystem for some Intel Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authentica…

Fix: 1.59+
Fix from $1,600 2020-08-13
Server Board S2600wt Firmware HIGH 8.2
CVE-2020-8721

Improper input validation for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to pote…

Fix: 1.59+
Fix from $1,950 2020-08-13
Json Pattern Validator CRITICAL 9.8
CVE-2020-17479

jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.

Fix: 2.2.2+
Fix from $2,300 2020-08-10
Tpeditor HIGH 7.8
CVE-2020-16227

Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not …

Fix: after 1.97
Fix from $1,950 2020-08-07
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16215

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied …

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
FreeBSD MEDIUM 6.8
CVE-2020-7459

In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missi…

Mitigation only
Fix from $1,600 2020-08-06
Fedora MEDIUM 6.5
CVE-2020-15112

In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-05