Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Istio HIGH 7.4
CVE-2020-8843

An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Ist…

Fix: after 1.3.6
Fix from $1,950 2020-02-14
Husky Rtu 6049 E70 Firmware HIGH 7.5
CVE-2019-20045

The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicio…

Fix: after 5.0
Fix from $1,950 2020-02-14
Device Manager MEDIUM 6.5
CVE-2018-21033

A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Adviso…

Fix: 4.2.0-00 / 8.6.2-00+
Fix from $1,600 2020-02-14
Ap4000w Firmware CRITICAL 9.8
CVE-2020-8614

An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by sending a specially crafted ne…

No fix yet
Fix from $2,300 2020-02-13
Globalprotect MEDIUM 5.5
CVE-2020-1976

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the …

Fix: after 5.0.5
Fix from $1,600 2020-02-12
Python Mode HIGH 8.8
CVE-2013-5106

A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.

No fix yet
Fix from $1,950 2020-02-12
Landscape Management HIGH 7.2
CVE-2020-6191

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Age…

Mitigation only
Fix from $1,950 2020-02-12
Landscape Management HIGH 7.2
CVE-2020-6192

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent …

Mitigation only
Fix from $1,950 2020-02-12
Wb55 MEDIUM 6.5
CVE-2019-19192

The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attr…

Fix: after 1.3.1
Fix from $1,600 2020-02-12
Fedora MEDIUM 5.3
CVE-2020-7957

The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet an…

Fix: 2.3.9.3+
Fix from $1,600 2020-02-12
Bearftp HIGH 7.5
CVE-2020-8815

Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via…

Fix: 0.3.1+
Fix from $1,950 2020-02-12
Pipeline\ HIGH 8.8
CVE-2020-2109

Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed m…

Fix: after 2.78
Fix from $1,950 2020-02-12
Script Security HIGH 8.8
CVE-2020-2110

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST trans…

Fix: after 1.69
Fix from $1,950 2020-02-12
Git CRITICAL 9.8
CVE-2014-9390EPSS 75%

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on…

Fix: 0.21.3 / 1.8.5.6+
Fix from $2,300 2020-02-12
Windows 10 MEDIUM 6.0
CVE-2020-0751

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a …

Patch available
Fix from $1,600 2020-02-11
Windows 10 MEDIUM 6.8
CVE-2020-0661

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest o…

Patch available
Fix from $1,600 2020-02-11
Pdfkit CRITICAL 9.8
CVE-2013-1607

Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability

Fix: 0.5.3+
Fix from $2,300 2020-02-11
Virtualization HIGH 8.8
CVE-2013-4535

The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag…

Fix: 1.7.2+
Fix from $1,950 2020-02-11
Chrome MEDIUM 5.4
CVE-2020-6411

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via…

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
Chrome MEDIUM 5.4
CVE-2020-6412

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via…

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
Chrome HIGH 8.8
CVE-2020-6416

Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11
Chrome MEDIUM 6.5
CVE-2020-6399

Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted …

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
Chrome MEDIUM 6.5
CVE-2020-6401

Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via…

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
Chrome HIGH 8.8
CVE-2020-6402

Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a mal…

Fix: 80.0.3987.87+
Fix from $1,950 2020-02-11
Mi Browser HIGH 8.8
CVE-2019-13322

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction …

Fix: 10.4.0+
Fix from $1,950 2020-02-10
Sphider CRITICAL 9.8
CVE-2014-5087EPSS 7%

A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user ex…

Fix: 1.3.6 / 3.2+
Fix from $2,300 2020-02-07
Status2k CRITICAL 9.8
CVE-2014-5091EPSS 15%

A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious use…

No fix yet
Fix from $2,300 2020-02-07
Railo HIGH 8.8
CVE-2014-5468EPSS 53%

A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG …

Fix: after 4.2.1.000
Fix from $1,950 2020-02-07
Android HIGH 8.8
CVE-2014-7224

A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityT…

Fix: 4.4+
Fix from $1,950 2020-02-07
Node.js CRITICAL 9.8
CVE-2019-15606EPSS 20%

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Fix: 10.19.0 / 12.15.0+
Fix from $2,300 2020-02-07