Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows Cleanup Assistant HIGH 7.8
CVE-2020-14956

In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified …

Mitigation only
Fix from $1,950 2020-06-30
Windows Cleanup Assistant HIGH 7.8
CVE-2020-14957

In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified …

Mitigation only
Fix from $1,950 2020-06-30
Cdp 1020mb Firmware HIGH 8.8
CVE-2019-19163

A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbitrary code, because of a usin…

Fix: after 2019.12.30
Fix from $1,950 2020-06-30
Coldfusion MEDIUM 6.5
CVE-2020-3767

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to a…

Mitigation only
Fix from $1,600 2020-06-26
Jiangmin Antivirus MEDIUM 5.5
CVE-2020-14955

In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified oth…

No fix yet
Fix from $1,600 2020-06-26
Factorytalk Services Platform HIGH 8.8
CVE-2020-12033

In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers…

Mitigation only
Fix from $1,950 2020-06-23
Freedroidrpg HIGH 7.8
CVE-2020-14939

An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A …

No fix yet
Fix from $1,950 2020-06-23
Keycloak MEDIUM 5.4
CVE-2020-1727

A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it al…

Fix: 9.0.2+
Fix from $1,600 2020-06-22
Cloudforms Management Engine HIGH 7.2
CVE-2019-14894

A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu…

Mitigation only
Fix from $1,950 2020-06-22
Total Security 2020 HIGH 8.8
CVE-2020-8102

Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web…

Fix: 24.0.20.116+
Fix from $1,950 2020-06-22
Apq8096au Firmware HIGH 7.8
CVE-2020-3676

Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consume…

Mitigation only
Fix from $1,950 2020-06-22
Apq8009 Firmware MEDIUM 5.5
CVE-2019-10626

Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage data in Snapdragon Auto, Snapdr…

Mitigation only
Fix from $1,600 2020-06-22
Apq8053 Firmware HIGH 7.8
CVE-2019-14047

While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Sn…

Mitigation only
Fix from $1,950 2020-06-22
Mattermost Server MEDIUM 5.3
CVE-2016-11067

An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.

Fix: 3.2.0+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18873

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) …

Fix: 4.1.2 / 4.2.1+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2018-21264

An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response.

Fix: 4.5.2 / 4.6.2+
Fix from $1,950 2020-06-19
Debian Linux HIGH 7.5
CVE-2020-8184

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2020-06-19
Strapi MEDIUM 6.5
CVE-2020-13961

Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable wit…

Fix: 3.0.2+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 7.5
CVE-2018-21262

An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX tex…

Fix: 4.7.3+
Fix from $1,950 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2018-21259

An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via…

Fix: 4.8.2 / 4.9.4+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20868

An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.

Fix: 4.10.8 / 5.7.3+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 7.5
CVE-2020-14459

An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020…

Fix: 5.19.0+
Fix from $1,950 2020-06-19
Mattermost Mobile HIGH 7.5
CVE-2019-20848

An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.

Fix: 1.26.0+
Fix from $1,950 2020-06-19
Asyncos MEDIUM 5.8
CVE-2020-3368

A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat…

Fix: 13.5.0+
Fix from $1,600 2020-06-18
Staros MEDIUM 5.3
CVE-2020-3244

A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthentic…

Fix: 21.18.0+
Fix from $1,600 2020-06-18
Webex Meetings HIGH 7.5
CVE-2020-3263

A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user syste…

Fix: 39.5.12+
Fix from $1,950 2020-06-18
Easergy T300 Firmware MEDIUM 5.3
CVE-2020-7504

A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable …

Fix: after 1.5.2
Fix from $1,600 2020-06-16
Open Xchange Appsuite HIGH 7.5
CVE-2020-8543

OX App Suite through 7.10.3 has Improper Input Validation.

No fix yet
Fix from $1,950 2020-06-16
Factorytalk Linx HIGH 8.1
CVE-2020-11999

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $1,950 2020-06-15
Factorytalk Linx CRITICAL 9.8
CVE-2020-12001EPSS 12%

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $2,300 2020-06-15