Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Alp Al00b Firmware MEDIUM 5.3
CVE-2019-5303

There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue bas…

Fix: 9.1.0.300 / 9.1.0.302+
Fix from $1,600 2020-04-27
Lion Al00c Firmware MEDIUM 5.5
CVE-2020-1880

Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability. An attacker crafted specially…

Fix: 10.0.0.205+
Fix from $1,600 2020-04-27
Ex3700 Firmware MEDIUM 6.5
CVE-2017-18747

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX…

Fix: 1.0.0.16 / 1.0.0.24+
Fix from $1,600 2020-04-23
Spectrum Protect CRITICAL 9.8
CVE-2020-4415EPSS 8%

IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote…

Fix: after 8.1.9.200
Fix from $2,300 2020-04-23
Fedora HIGH 7.5
CVE-2020-12066

CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.

Fix: 0.7.5+
Fix from $1,950 2020-04-22
Gs110emx Firmware MEDIUM 6.5
CVE-2018-21122

Certain NETGEAR devices are affected by denial of service. This affects GS110EMX before 1.0.0.9, GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and…

Fix: 1.0.0.5 / 1.0.0.6+
Fix from $1,600 2020-04-22
Jnr1010 Firmware MEDIUM 6.5
CVE-2017-18763

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JNR1010v2 before 1.1.0.42, JR6150 before 1.0.1.10,…

Fix: 1.0.0.18 / 1.0.0.30+
Fix from $1,600 2020-04-22
Xr500 Firmware HIGH 8.8
CVE-2018-21115

NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.

Fix: 2.3.2.32+
Fix from $1,950 2020-04-22
D6220 Firmware MEDIUM 5.5
CVE-2017-18778

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6220 before 1.0.0.28, D6400 before 1.0.0.60, D700…

Fix: 1.0.0.28 / 1.0.0.38+
Fix from $1,600 2020-04-22
D3600 Firmware MEDIUM 6.5
CVE-2018-21140

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

Fix: 1.0.0.76+
Fix from $1,600 2020-04-21
Git HIGH 7.5
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This b…

Fix: 2.17.5 / 2.18.4+
Fix from $1,950 2020-04-21
R6700 Firmware MEDIUM 6.2
CVE-2017-18798

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, D7…

Fix: 1.0.0.25 / 1.0.1.50+
Fix from $1,600 2020-04-21
R6200 Firmware HIGH 7.5
CVE-2017-18799

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6200v2 before 1.0.3.14, R6250 before 1.0.4.8, R63…

Fix: 1.0.0.30 / 1.0.0.56+
Fix from $1,950 2020-04-21
R7800 Firmware MEDIUM 6.2
CVE-2017-18803

NETGEAR R7800 devices before 1.0.2.30 are affected by incorrect configuration of security settings.

Fix: 1.0.2.30+
Fix from $1,600 2020-04-21
Joomla\! MEDIUM 5.3
CVE-2020-11890

An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.

Fix: 3.9.17+
Fix from $1,600 2020-04-21
Undertow HIGH 8.1
CVE-2020-1757

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.…

Fix: 2.1.0+
Fix from $1,950 2020-04-21
M4300 28g Firmware MEDIUM 6.2
CVE-2017-18840

Certain NETGEAR devices are affected by denial of service. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before…

Fix: 12.0.2.15+
Fix from $1,600 2020-04-20
Openmrs MEDIUM 6.1
CVE-2020-5728

OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is ins…

Fix: after 2.9.0
Fix from $1,600 2020-04-17
Android CRITICAL 9.8
CVE-2019-20778

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Backup subsystem does not properly restri…

Mitigation only
Fix from $2,300 2020-04-17
Mivoice Connect CRITICAL 9.8
CVE-2020-10211

A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to exe…

Fix: 22.11.4900.0+
Fix from $2,300 2020-04-17
Shopizer MEDIUM 6.5
CVE-2020-11007

In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shop…

Fix: 2.11.0+
Fix from $1,600 2020-04-16
Msm8998 Firmware CRITICAL 9.1
CVE-2020-3652

Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check of length of variab…

Mitigation only
Fix from $2,300 2020-04-16
Msm8998 Firmware CRITICAL 9.1
CVE-2020-3653

Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon Compute, S…

Mitigation only
Fix from $2,300 2020-04-16
5508 Wireless Controller Firmware HIGH 7.5
CVE-2020-3262

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software c…

Mitigation only
Fix from $1,950 2020-04-15
Iot Field Network Director HIGH 7.5
CVE-2020-3162

A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remo…

Fix: 4.6.0+
Fix from $1,950 2020-04-15
Webex Network Recording Player HIGH 7.8
CVE-2020-3194

A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to…

Fix: 1.3.48 / 4.0+
Fix from $1,950 2020-04-15
Ucs Director HIGH 8.8
CVE-2020-3239EPSS 74%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $1,950 2020-04-15
Ucs Director HIGH 7.3
CVE-2020-3240EPSS 39%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $1,950 2020-04-15
Ucs Director CRITICAL 9.8
CVE-2020-3243EPSS 88%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $2,300 2020-04-15
Ucs Director CRITICAL 9.8
CVE-2020-3247EPSS 75%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $2,300 2020-04-15