Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS MEDIUM 6.0
CVE-2020-3201

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local at…

Patch available
Fix from $1,600 2020-06-03
Sm8250 Firmware HIGH 7.8
CVE-2020-3623

kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130

No fix yet
Fix from $1,950 2020-06-02
Apq8009 Firmware HIGH 7.1
CVE-2019-14038

Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in command response in Snapdragon A…

Patch available
Fix from $1,950 2020-06-02
Engine MEDIUM 6.0
CVE-2020-13401

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertis…

Fix: 19.03.11+
Fix from $1,600 2020-06-02
Fortiap S MEDIUM 6.5
CVE-2019-15709

An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized admi…

Fix: after 6.2.2
Fix from $1,600 2020-06-01
Openssh HIGH 7.5
CVE-2020-12062

The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivi…

Patch available
Fix from $1,950 2020-06-01
F680 Firmware MEDIUM 6.5
CVE-2020-6868

There is an input validation vulnerability in a PON terminal product of ZTE, which supports the creation of WAN connections through WEB management pa…

Mitigation only
Fix from $1,600 2020-06-01
Windows Master HIGH 7.8
CVE-2020-13634

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service …

No fix yet
Fix from $1,950 2020-05-29
Security Identity Governance And Intelligence MEDIUM 6.5
CVE-2020-4231

IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized commands due to hazardous input val…

Patch available
Fix from $1,600 2020-05-28
Firefox CRITICAL 10.0
CVE-2020-12388

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 10.0
CVE-2020-12389

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Desktop CRITICAL 9.8
CVE-2020-5537

Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.

Fix: after 2.2.40
Fix from $2,300 2020-05-25
Prime Network Registrar HIGH 7.5
CVE-2020-3272

A vulnerability in the DHCP server of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS…

Fix: 8.3.7.1 / 9.1.3+
Fix from $1,950 2020-05-22
Unified Contact Center Express CRITICAL 9.8
CVE-2020-3280EPSS 7%

A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote …

Fix: 12.0+
Fix from $2,300 2020-05-22
Advanced Malware Protection For Endpoints MEDIUM 6.1
CVE-2020-3314

A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine to crash during the scan of lo…

Fix: 1.12.3.738+
Fix from $1,600 2020-05-22
Edge MEDIUM 5.9
CVE-2020-1195

An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input, aka 'Micros…

Patch available
Fix from $1,600 2020-05-21
Power Bi Report Server MEDIUM 6.8
CVE-2020-1173

A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticate…

Patch available
Fix from $1,600 2020-05-21
Windows 10 HIGH 7.8
CVE-2020-1081

An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers. An aut…

Patch available
Fix from $1,950 2020-05-21
Windows 10 MEDIUM 5.5
CVE-2020-1084

A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker…

Patch available
Fix from $1,600 2020-05-21
Moodle HIGH 8.8
CVE-2020-10738

A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was…

Fix: 3.5.12 / 3.6.10+
Fix from $1,950 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6485

Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer proces…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Superdome Flex Server Firmware MEDIUM 6.7
CVE-2020-7137

A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Flex Server version 3.25.46 or l…

Fix: 3.25.46+
Fix from $1,600 2020-05-19
Resteasy HIGH 7.5
CVE-2020-1695

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v…

Fix: 3.12.0 / 4.6.0+
Fix from $1,950 2020-05-19
Spectrum Scale HIGH 7.1
CVE-2020-4411

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its…

Fix: after 5.0.4.3
Fix from $1,950 2020-05-19
Dovecot MEDIUM 5.3
CVE-2020-10967EPSS 8%

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

Fix: 2.3.10.1+
Fix from $1,600 2020-05-18
Naviserver HIGH 7.5
CVE-2020-13111

NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A…

Fix: after 4.99.19
Fix from $1,950 2020-05-16
Apt MEDIUM 5.5
CVE-2020-3810

Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafte…

Fix: 2.1.2+
Fix from $1,600 2020-05-15
Engines HIGH 7.5
CVE-2020-8100

Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker to trigger a denial of servi…

Fix: 7.84063+
Fix from $1,950 2020-05-15
Pan Os HIGH 7.5
CVE-2020-2011

An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user…

Fix: 8.1.14 / 9.1.0+
Fix from $1,950 2020-05-13
Keycloak HIGH 8.8
CVE-2020-1714

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an…

Fix: 11.0.0+
Fix from $1,950 2020-05-13