Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.5
CVE-2017-18685

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash…

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2017-18674

An issue was discovered on Samsung mobile devices with N(7.0) software. The time service (aka Timaservice) allows a kernel panic. The Samsung ID is S…

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2017-18676

An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm chipsets) software. There is an RKP kernel protection bypass (in which unwant…

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2017-18679

An issue was discovered on Samsung mobile devices with M(6.0) software. SLocation can cause a system crash via a call to an API that is not implement…

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.1
CVE-2017-18680

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interface allows Add User actions, le…

Mitigation only
Fix from $1,950 2020-04-07
Android CRITICAL 9.1
CVE-2017-18648

An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file read/write operations can occur…

Mitigation only
Fix from $2,300 2020-04-07
Npm Programmatic CRITICAL 9.8
CVE-2020-7614

npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validatio…

Fix: after 0.0.12
Fix from $2,300 2020-04-07
Android HIGH 7.5
CVE-2016-11031

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. …

Mitigation only
Fix from $1,950 2020-04-07
Android MEDIUM 5.3
CVE-2016-11032

An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotecte…

Mitigation only
Fix from $1,600 2020-04-07
Android HIGH 7.8
CVE-2016-11052

An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a …

Mitigation only
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2016-11046

An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reac…

Mitigation only
Fix from $1,950 2020-04-07
Utils Extend CRITICAL 9.8
CVE-2020-8147

Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code ex…

Fix: after 1.0.8
Fix from $2,300 2020-04-03
Esoms MEDIUM 5.4
CVE-2019-19095

Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Fortios HIGH 8.8
CVE-2018-13371

An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via conn…

Fix: after 6.0.2
Fix from $1,950 2020-04-02
Nexus HIGH 7.2
CVE-2020-10204EPSS 38%

Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

Fix: 3.21.2+
Fix from $1,950 2020-04-01
Mac Os X CRITICAL 9.8
CVE-2020-3847

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to l…

Fix: 10.15.3+
Fix from $2,300 2020-04-01
Mac Os X CRITICAL 9.8
CVE-2020-3848

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able …

Fix: 10.15.3+
Fix from $2,300 2020-04-01
Mac Os X CRITICAL 9.8
CVE-2020-3849

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able …

Fix: 10.15.3+
Fix from $2,300 2020-04-01
Mac Os X CRITICAL 9.8
CVE-2020-3850

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able …

Fix: 10.15.3+
Fix from $2,300 2020-04-01
Mac Os X HIGH 7.8
CVE-2020-3892

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be…

Fix: 10.15.4+
Fix from $1,950 2020-04-01
Mac Os X HIGH 7.8
CVE-2020-3893

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be…

Fix: 10.15.4+
Fix from $1,950 2020-04-01
Mac Os X HIGH 7.8
CVE-2020-3905

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be…

Fix: 10.15.4+
Fix from $1,950 2020-04-01
Mac Os X MEDIUM 6.1
CVE-2020-3884

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbi…

Fix: 10.15.4+
Fix from $1,600 2020-04-01
Ansible Engine MEDIUM 5.6
CVE-2019-14905

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos…

Fix: 2.7.16 / 2.8.8+
Fix from $1,600 2020-03-31
Spectrum Protect Plus HIGH 7.5
CVE-2020-4214

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-s…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Spectrum Protect Plus HIGH 8.8
CVE-2020-4206

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user…

Fix: after 10.1.5
Fix from $1,950 2020-03-31
Prtg Network Monitor CRITICAL 9.8
CVE-2020-10374

A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST req…

Fix: after 20.1.56
Fix from $2,300 2020-03-30
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10885EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…

Mitigation only
Fix from $2,300 2020-03-25
Pipeline\ HIGH 8.8
CVE-2020-2166

Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in …

Fix: after 1.40
Fix from $1,950 2020-03-25
Openshift Pipeline HIGH 8.8
CVE-2020-2167

Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in…

Fix: after 1.0.56
Fix from $1,950 2020-03-25