Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Azure Container Service HIGH 8.8
CVE-2020-2168

Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resultin…

Fix: after 1.0.1
Fix from $1,950 2020-03-25
Shihonkanri Plus Goout CRITICAL 9.1
CVE-2020-5555

Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is pl…

Mitigation only
Fix from $2,300 2020-03-25
Insync HIGH 7.8
CVE-2019-4001

Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.

No fix yet
Fix from $1,950 2020-03-24
Android CRITICAL 9.8
CVE-2020-10837

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and a…

Mitigation only
Fix from $2,300 2020-03-24
Fedora CRITICAL 9.8
CVE-2020-1747EPSS 5%

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes …

Fix: 5.3.1+
Fix from $2,300 2020-03-24
Chrome MEDIUM 5.4
CVE-2020-6425

Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious…

Fix: 80.0.3987.149+
Fix from $1,600 2020-03-23
Asuswrt HIGH 7.5
CVE-2018-20335

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= …

No fix yet
Fix from $1,950 2020-03-20
U Boot HIGH 7.8
CVE-2020-10648

Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT im…

Fix: 2018.03+
Fix from $1,950 2020-03-19
Libvirt MEDIUM 5.7
CVE-2019-20485

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a…

Fix: 6.0.0+
Fix from $1,600 2020-03-19
Suitecrm HIGH 7.5
CVE-2020-8787

SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.

Fix: 7.10.23 / 7.11.11+
Fix from $1,950 2020-03-16
Bitcoin Core HIGH 7.5
CVE-2017-12842

Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that pa…

Fix: 0.14.0+
Fix from $1,950 2020-03-16
Joomla\! MEDIUM 5.3
CVE-2020-10240

An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames …

Fix: 3.9.16+
Fix from $1,600 2020-03-16
Centro Grande Firmware HIGH 7.5
CVE-2019-19942

Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 b…

Fix: 6.14.06 / 7.10.18+
Fix from $1,950 2020-03-16
Fortios MEDIUM 6.1
CVE-2019-6696

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an…

Fix: after 6.0.8
Fix from $1,600 2020-03-15
Android HIGH 7.3
CVE-2019-2216

In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privileg…

Mitigation only
Fix from $1,950 2020-03-15
Responsive Filemanager CRITICAL 9.8
CVE-2020-10567EPSS 19%

An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is n…

Fix: after 9.14.0
Fix from $2,300 2020-03-14
Graphics Driver MEDIUM 5.5
CVE-2020-0567

Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to enable denial of service via …

Fix: 26.20.100.7212+
Fix from $1,600 2020-03-12
Nuc Kit Nuc8i7bek Firmware MEDIUM 6.7
CVE-2020-0526

Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. Th…

Mitigation only
Fix from $1,600 2020-03-12
Kde Applications MEDIUM 5.3
CVE-2018-19516

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equ…

Fix: 18.12+
Fix from $1,600 2020-03-12
Windows 10 HIGH 7.8
CVE-2020-0808

An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Eleva…

Patch available
Fix from $1,950 2020-03-12
Fat Free Framework CRITICAL 9.8
CVE-2020-5203

In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GE…

Patch available
Fix from $2,300 2020-03-11
Netweaver Application Server Java HIGH 7.2
CVE-2020-6202

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate th…

Mitigation only
Fix from $1,950 2020-03-10
Android MEDIUM 6.7
CVE-2020-0050

In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalati…

Patch available
Fix from $1,600 2020-03-10
Android HIGH 7.8
CVE-2020-0041 KEV

In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2020-03-10
Entrapass CRITICAL 9.8
CVE-2019-7589

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code …

Fix: 8.10+
Fix from $2,300 2020-03-10
Sinvr\/sivms Video Server HIGH 7.5
CVE-2019-19298

A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2). …

Patch available
Fix from $1,950 2020-03-10
Siprotec 4 HIGH 7.5
CVE-2019-19279

A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Spec…

Mitigation only
Fix from $1,950 2020-03-10
Ddr4 Sdram CRITICAL 9.0
CVE-2020-10255

Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations against RowHammer attacks known …

Mitigation only
Fix from $2,300 2020-03-10
GitLab MEDIUM 5.3
CVE-2019-12433

An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settin…

Fix: after 11.11.0
Fix from $1,600 2020-03-10
Froxlor MEDIUM 6.1
CVE-2020-10236

An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was n…

Fix: 0.10.14+
Fix from $1,600 2020-03-09