Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ucs Director CRITICAL 9.8
CVE-2020-3248EPSS 74%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $2,300 2020-04-15
Ucs Director HIGH 7.5
CVE-2020-3249EPSS 23%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $1,950 2020-04-15
Ucs Director CRITICAL 9.8
CVE-2020-3250EPSS 60%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $2,300 2020-04-15
Ucs Director HIGH 8.8
CVE-2020-3251EPSS 62%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $1,950 2020-04-15
Ucs Director MEDIUM 6.5
CVE-2020-3252EPSS 5%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $1,600 2020-04-15
Ip Phone 8865 Firmware CRITICAL 9.8
CVE-2020-3161 KEVEPSS 84%

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a…

Mitigation only
Fix from $2,300 2020-04-15
Ubuntu Linux HIGH 7.5
CVE-2019-12520

An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does th…

Fix: after 4.7
Fix from $1,950 2020-04-15
Vrealize Log Insight MEDIUM 6.1
CVE-2020-3954

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

Fix: 8.1.0+
Fix from $1,600 2020-04-15
Document Server CRITICAL 9.8
CVE-2020-11534

An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function …

Mitigation only
Fix from $2,300 2020-04-15
Document Server CRITICAL 9.8
CVE-2020-11536

An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite …

Mitigation only
Fix from $2,300 2020-04-15
Autoupdate HIGH 7.8
CVE-2020-0984

An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing …

Patch available
Fix from $1,950 2020-04-15
Windows 10 HIGH 8.4
CVE-2020-0910EPSS 9%

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2020-04-15
Vm Virtualbox HIGH 8.2
CVE-2020-2908

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.40 / 6.0.20+
Fix from $1,950 2020-04-15
Vm Virtualbox HIGH 7.5
CVE-2020-2907

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.40 / 6.0.20+
Fix from $1,950 2020-04-15
Git HIGH 7.5
CVE-2020-5260EPSS 10%

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us…

Fix: 2.17.4 / 2.18.3+
Fix from $1,950 2020-04-14
System Interface Foundation MEDIUM 5.5
CVE-2020-8324

A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow uns…

Fix: 1.2.184.31+
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2020-6227

SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to s…

Mitigation only
Fix from $1,950 2020-04-14
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2020-4151

IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-For…

Fix: after 7.3.3
Fix from $1,600 2020-04-14
Junos MEDIUM 6.5
CVE-2020-1633

Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Br…

Mitigation only
Fix from $1,600 2020-04-09
Junos MEDIUM 6.7
CVE-2020-1619

A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Next-Generation Routing Engine …

Mitigation only
Fix from $1,600 2020-04-08
Secdo HIGH 7.8
CVE-2020-1984

Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access t…

Mitigation only
Fix from $1,950 2020-04-08
Secdo MEDIUM 5.5
CVE-2020-1986

Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS…

Mitigation only
Fix from $1,600 2020-04-08
Android MEDIUM 6.2
CVE-2018-21068

An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a pas…

Mitigation only
Fix from $1,600 2020-04-08
Android HIGH 7.5
CVE-2018-21078

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate vi…

Mitigation only
Fix from $1,950 2020-04-08
Android CRITICAL 9.8
CVE-2018-21055

An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software. A device can be rooted with a custom…

Mitigation only
Fix from $2,300 2020-04-08
Android MEDIUM 6.5
CVE-2018-21092

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via…

Mitigation only
Fix from $1,600 2020-04-08
Cross Domain Local Storage HIGH 7.1
CVE-2015-9544

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any vali…

Fix: after 2.0.5
Fix from $1,950 2020-04-07
Cross Domain Local Storage HIGH 7.1
CVE-2015-9545

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the …

Fix: after 2.0.5
Fix from $1,950 2020-04-07
Android CRITICAL 9.8
CVE-2017-18683

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows Hare Hunting during application installation. Th…

No fix yet
Fix from $2,300 2020-04-07
Android CRITICAL 9.8
CVE-2017-18684

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows provider seizure via an application that uses a …

Mitigation only
Fix from $2,300 2020-04-07