Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
FreeBSD CRITICAL 9.8
CVE-2020-7454

In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias …

Mitigation only
Fix from $2,300 2020-05-13
FreeBSD CRITICAL 9.8
CVE-2019-15880

In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffe…

Mitigation only
Fix from $2,300 2020-05-13
Iubenda Cookie Law Solution MEDIUM 6.1
CVE-2020-12742

The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.

Fix: 2.3.5+
Fix from $1,600 2020-05-13
Clam Antivirus HIGH 7.5
CVE-2020-3327EPSS 5%

A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacke…

Fix: after 0.102.2
Fix from $1,950 2020-05-13
Clam Antivirus HIGH 7.5
CVE-2020-3341

A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote…

Fix: after 0.102.2
Fix from $1,950 2020-05-13
Adaptive Server Enterprise Backup Server HIGH 7.2
CVE-2020-6248

SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while execut…

Mitigation only
Fix from $1,950 2020-05-12
Zephyr HIGH 7.8
CVE-2020-10028

Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versio…

Patch available
Fix from $1,950 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10058

Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated …

Patch available
Fix from $1,950 2020-05-11
Android HIGH 7.5
CVE-2020-12752

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a bru…

Mitigation only
Fix from $1,950 2020-05-11
Pip HIGH 7.8
CVE-2018-20225

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtai…

Mitigation only
Fix from $1,950 2020-05-08
Dext5 HIGH 8.8
CVE-2019-19164

dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by set…

Mitigation only
Fix from $1,950 2020-05-07
Wl Wn575a3 Firmware HIGH 8.8
CVE-2020-10971

An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the sup…

Mitigation only
Fix from $1,950 2020-05-07
Zoneplayer HIGH 8.8
CVE-2020-7803

IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.o…

Mitigation only
Fix from $1,950 2020-05-07
Intelligent Power Manager HIGH 7.3
CVE-2020-6651

Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allow…

Fix: after 1.67
Fix from $1,950 2020-05-07
Ntp MEDIUM 5.3
CVE-2018-8956

ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadc…

Mitigation only
Fix from $1,600 2020-05-06
Dolibarr HIGH 8.8
CVE-2020-12669

core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric me…

Fix: 11.0.4+
Fix from $1,950 2020-05-06
Secure Firewall Management Center HIGH 8.1
CVE-2020-3302

A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on…

Fix: 6.2.2.2+
Fix from $1,950 2020-05-06
Secure Firewall Management Center MEDIUM 5.3
CVE-2020-3307

A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary …

Mitigation only
Fix from $1,600 2020-05-06
Firepower Device Manager On Box HIGH 7.2
CVE-2020-3309

A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on…

Fix: 6.2.3+
Fix from $1,950 2020-05-06
Secure Firewall Threat Defense HIGH 8.6
CVE-2020-3191

A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-05-06
Hibernate Validator MEDIUM 5.3
CVE-2020-10693

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evalua…

Fix: 6.0.20 / 6.1.5+
Fix from $1,600 2020-05-06
D6100 Firmware MEDIUM 6.8
CVE-2017-18867

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55, D7800 before V1.0.1.24, R71…

Fix: 1.0.0.32 / 1.0.0.48+
Fix from $1,600 2020-05-05
Laquis Scada HIGH 7.8
CVE-2020-10622

LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users

Fix: after 4.3.1
Fix from $1,950 2020-05-04
Ios Xe HIGH 7.8
CVE-2019-16011

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are execute…

Fix: 17.2.1r+
Fix from $1,950 2020-04-29
800xa System HIGH 7.5
CVE-2020-8475

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $1,950 2020-04-29
800xa System HIGH 7.5
CVE-2020-8476

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $1,950 2020-04-29
FreeBSD CRITICAL 9.8
CVE-2019-15874

In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, inco…

Patch available
Fix from $2,300 2020-04-29
FreeBSD CRITICAL 9.8
CVE-2019-5614

In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, inco…

Patch available
Fix from $2,300 2020-04-29
Json HIGH 7.5
CVE-2020-10663EPSS 7%

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulne…

Fix: after 2.2.0
Fix from $1,950 2020-04-28
Alp Al00b Firmware MEDIUM 5.3
CVE-2019-5302

There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue bas…

Fix: 9.1.0.300 / 9.1.0.302+
Fix from $1,600 2020-04-27