Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ipq8074 Firmware CRITICAL 9.1
CVE-2019-14082

Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Snapdragon Consumer Electronics…

Mitigation only
Fix from $2,300 2020-03-05
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10552

Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cmd in Snapdragon Aut…

No fix yet
Fix from $2,300 2020-03-05
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10577

Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to denial of service in Snapdrago…

Mitigation only
Fix from $2,300 2020-03-05
Zammad HIGH 7.5
CVE-2020-10101

An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message…

Fix: after 3.2.0
Fix from $1,950 2020-03-05
Webex Meetings HIGH 7.8
CVE-2020-3127

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an at…

Fix: 1.3.43 / 3.0+
Fix from $1,950 2020-03-04
Webex Meetings HIGH 7.8
CVE-2020-3128

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an at…

Fix: 1.3.49 / 3.0+
Fix from $1,950 2020-03-04
Cloud Email Security MEDIUM 5.3
CVE-2020-3164

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), …

Fix: 13.6.0+
Fix from $1,600 2020-03-04
Reactor Netty HIGH 7.5
CVE-2020-5403

Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of…

Mitigation only
Fix from $1,950 2020-03-03
Pdf Image CRITICAL 9.8
CVE-2020-8132

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based …

Fix: after 2.0.0
Fix from $2,300 2020-02-28
Wireshark HIGH 7.5
CVE-2020-9430

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg…

Fix: after 3.2.1
Fix from $1,950 2020-02-27
Icloud HIGH 8.8
CVE-2020-3846

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3…

Fix: 6.1.2 / 7.17+
Fix from $1,950 2020-02-27
Ipados HIGH 7.8
CVE-2020-3856

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, …

Fix: 6.1.2 / 10.15.3+
Fix from $1,950 2020-02-27
Ipados HIGH 7.8
CVE-2020-3860

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, watchOS 6.1.2. An applic…

Fix: 6.1.2 / 13.3.1+
Fix from $1,950 2020-02-27
Mac Os X MEDIUM 5.5
CVE-2020-3839

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read …

Fix: 10.15.3+
Fix from $1,600 2020-02-27
Nx Os MEDIUM 5.3
CVE-2020-3170

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to un…

Fix: 8.2 / 8.4+
Fix from $1,600 2020-02-26
Firepower Extensible Operating System HIGH 8.8
CVE-2020-3172

A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent atta…

Fix: 2.6.1.187 / 2.7.1.106+
Fix from $1,950 2020-02-26
Secure Firewall Threat Defense MEDIUM 6.7
CVE-2020-3166

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying ope…

Fix: 2.2.2.97 / 2.3.1.155+
Fix from $1,600 2020-02-26
Visual Access Manager MEDIUM 6.5
CVE-2019-19992

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to read XML files on the fi…

Fix: after 4.29.0
Fix from $1,600 2020-02-26
Spectrum Protect CRITICAL 9.8
CVE-2020-4212EPSS 15%

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …

Fix: 10.1.5+
Fix from $2,300 2020-02-24
Uap Core HIGH 7.5
CVE-2020-5243

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular …

Fix: 0.7.3+
Fix from $1,950 2020-02-21
Vivid E95 Firmware MEDIUM 6.8
CVE-2020-6977

A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow …

Mitigation only
Fix from $1,600 2020-02-20
Moped HIGH 7.5
CVE-2015-4410EPSS 6%

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a den…

Patch available
Fix from $1,950 2020-02-20
Ansible CRITICAL 9.8
CVE-2014-4657

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.5.4+
Fix from $2,300 2020-02-20
FreeBSD MEDIUM 6.5
CVE-2015-2923

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to reconfigure a hop-limit sett…

Fix: 10.1+
Fix from $1,600 2020-02-20
Meeting Server MEDIUM 5.3
CVE-2020-3160

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, rem…

Fix: 2.8.0+
Fix from $1,600 2020-02-19
Jclouds CRITICAL 9.8
CVE-2014-4651

It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc…

Fix: 1.8.0+
Fix from $2,300 2020-02-18
Gecko Cms CRITICAL 9.8
CVE-2015-1425

JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities

No fix yet
Fix from $2,300 2020-02-18
Gaussdb 200 HIGH 8.8
CVE-2020-1811

GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions…

Mitigation only
Fix from $1,950 2020-02-18
Nip6800 Firmware HIGH 7.5
CVE-2020-1828

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC…

Mitigation only
Fix from $1,950 2020-02-17
Zabbix CRITICAL 9.8
CVE-2013-3738

A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali…

Patch available
Fix from $2,300 2020-02-17