Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Fedora MEDIUM 6.5
CVE-2020-15106

In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-05
Antivirus Toolkit MEDIUM 6.7
CVE-2020-8607

An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could…

Fix: 1.62.1240+
Fix from $1,600 2020-08-05
Solidus MEDIUM 5.3
CVE-2020-15109

In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerab…

Fix: 2.8.6 / 2.9.6+
Fix from $1,600 2020-08-04
Daviewindy HIGH 7.8
CVE-2020-7822

DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers …

Fix: after 8.98.7
Fix from $1,950 2020-08-04
Daviewindy HIGH 7.8
CVE-2020-7823

DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers co…

Fix: after 8.98.7
Fix from $1,950 2020-08-04
Trb245 Firmware HIGH 7.5
CVE-2020-5771

Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a mal…

No fix yet
Fix from $1,950 2020-08-03
Keepassrpc CRITICAL 9.1
CVE-2020-16272

The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers …

Fix: 1.12.0+
Fix from $2,300 2020-08-03
Data Center Network Manager HIGH 8.8
CVE-2020-3383EPSS 7%

A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory…

Fix: 11.4+
Fix from $1,950 2020-07-31
Sd Wan CRITICAL 9.8
CVE-2020-3375

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. T…

Fix: 18.4.5 / 19.2.2+
Fix from $2,300 2020-07-31
Apq8009 Firmware CRITICAL 9.8
CVE-2020-3698

Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response frame in Snapdragon Auto, Snap…

Patch available
Fix from $2,300 2020-07-30
Kamorta Firmware HIGH 7.8
CVE-2019-14123

Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in…

Mitigation only
Fix from $1,950 2020-07-30
Mediace CRITICAL 9.8
CVE-2020-15086

In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification…

Fix: 7.6.5+
Fix from $2,300 2020-07-29
TYPO3 HIGH 8.8
CVE-2020-15098

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
TYPO3 HIGH 8.1
CVE-2020-15099

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attack…

Fix: 9.5.20 / 10.4.6+
Fix from $1,950 2020-07-29
Easergy Builder HIGH 7.5
CVE-2020-7518

A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify proje…

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
C More Hmi Ea9 Firmware HIGH 7.5
CVE-2020-10922

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 …

Mitigation only
Fix from $1,950 2020-07-23
Adaptive Security Appliance Software HIGH 7.5
CVE-2020-3452 KEVEPSS 100%

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-07-22
Chrome HIGH 8.8
CVE-2020-6507EPSS 19%

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 83.0.4103.106+
Fix from $1,950 2020-07-22
Sails HIGH 7.5
CVE-2018-21036

Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in sails-hook-sockets…

Fix: 1.0.0-46+
Fix from $1,950 2020-07-21
Factorytalk View HIGH 7.8
CVE-2020-12029EPSS 47%

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be…

No fix yet
Fix from $1,950 2020-07-20
P30 Pro Firmware HIGH 7.8
CVE-2020-9254

HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earl…

Fix: 10.1.0.123 / 10.1.0.126+
Fix from $1,950 2020-07-17
Honor 10 Firmware MEDIUM 5.5
CVE-2020-9255

Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. Certain service in the system …

Fix: 10.0.0.178+
Fix from $1,600 2020-07-17
Daviewindy HIGH 7.8
CVE-2020-7818

DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Davie…

Fix: after 8.98.9
Fix from $1,950 2020-07-17
Junos HIGH 7.5
CVE-2020-1640

An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon…

Mitigation only
Fix from $1,950 2020-07-17
Junos HIGH 7.5
CVE-2020-1644

On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE packet causes an internal counter to be incremented i…

Mitigation only
Fix from $1,950 2020-07-17
Sonicos MEDIUM 5.3
CVE-2020-5130

SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This…

Fix: after 6.5.4.4-44n
Fix from $1,600 2020-07-17
Netextender HIGH 7.8
CVE-2020-5131

SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with …

Fix: after 9.0.815
Fix from $1,950 2020-07-17
Sd Wan Firmware HIGH 8.8
CVE-2020-3387EPSS 13%

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected sy…

Fix: 19.2.3 / 20.1.1.1+
Fix from $1,950 2020-07-16
Rv340 Dual Wan Gigabit Vpn Router Firmware CRITICAL 9.8
CVE-2020-3357

A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers c…

Fix: 1.0.03.18+
Fix from $2,300 2020-07-16
Rv340 Dual Wan Gigabit Vpn Router Firmware HIGH 8.6
CVE-2020-3358

A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker…

Fix: 1.0.03.18+
Fix from $1,950 2020-07-16