Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Forticlient MEDIUM 6.5
CVE-2019-16152

A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes …

Fix: after 6.2.1
Fix from $1,600 2020-02-06
Bonjour MEDIUM 5.5
CVE-2011-0220

Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

Fix: 2011+
Fix from $1,600 2020-02-05
Coppermine Gallery CRITICAL 9.8
CVE-2010-4815

Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

Fix: 1.4.26+
Fix from $2,300 2020-02-05
Video Surveillance 8400 Ip Camera Firmware HIGH 8.8
CVE-2020-3110EPSS 6%

A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated…

Fix: 1.0.7+
Fix from $1,950 2020-02-05
Ip Conference Phone 7832 Firmware HIGH 8.8
CVE-2020-3111

A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely e…

Fix: 11.3 / 12.7+
Fix from $1,950 2020-02-05
Url Parse MEDIUM 5.3
CVE-2020-8124

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass securit…

Fix: after 1.4.4
Fix from $1,600 2020-02-04
Klona CRITICAL 9.8
CVE-2020-8125

Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution…

Fix: after 1.1.0
Fix from $2,300 2020-02-04
Ubuntu Linux HIGH 7.5
CVE-2020-8517EPSS 7%

An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may w…

Fix: 4.10+
Fix from $1,950 2020-02-04
Nextcloud Server HIGH 8.0
CVE-2019-15613

A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.

Fix: 15.0.14 / 16.0.7+
Fix from $1,950 2020-02-04
Htcondor HIGH 8.8
CVE-2014-8126

The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

Fix: 8.2.6+
Fix from $1,950 2020-01-31
Airwave CRITICAL 9.8
CVE-2016-2031EPSS 5%

Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient ch…

Fix: 4.1.3.0 / 8.2.0.0+
Fix from $2,300 2020-01-31
Total Security 2020 MEDIUM 5.5
CVE-2020-8095

A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial…

Fix: 24.9+
Fix from $1,600 2020-01-30
Sg200 50 Firmware HIGH 7.5
CVE-2020-3147

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…

Fix: 1.3.7.18+
Fix from $1,950 2020-01-30
Ossec CRITICAL 9.8
CVE-2020-8445

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from pr…

Fix: after 3.5.0
Fix from $2,300 2020-01-30
Tensorflow HIGH 7.5
CVE-2020-5215

In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the f…

Fix: 1.15.2 / 2.0.1+
Fix from $1,950 2020-01-28
Mq Appliance HIGH 7.8
CVE-2019-4620

IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables.…

Fix: 8.0.0.14 / 9.1.0.4+
Fix from $1,950 2020-01-28
Fish CRITICAL 9.8
CVE-2014-2914

fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to ex…

Fix: 2.1.1+
Fix from $2,300 2020-01-28
Xpient Iris CRITICAL 9.8
CVE-2013-2571EPSS 16%

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted reques…

Fix: after 3.8
Fix from $2,300 2020-01-28
GitLab CRITICAL 9.8
CVE-2019-5464

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the li…

Fix: 11.11.7+
Fix from $2,300 2020-01-28
D3g0804w Firmware CRITICAL 9.8
CVE-2020-8087EPSS 6%

SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as de…

No fix yet
Fix from $2,300 2020-01-27
Lustre HIGH 7.5
CVE-2019-20430

In the Lustre file system before 2.12.3, the mdt module has an LBUG panic (via a large MDT Body eadatasize field) due to the lack of validation for s…

Fix: 2.12.3+
Fix from $1,950 2020-01-27
Smart Software Manager On Prem CRITICAL 9.1
CVE-2019-16029

A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacke…

Fix: 7-201910+
Fix from $2,300 2020-01-26
Email Security Appliance MEDIUM 6.5
CVE-2020-3134

A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, re…

Fix: 13.0+
Fix from $1,600 2020-01-26
Application Policy Infrastructure Controller MEDIUM 5.3
CVE-2020-3139

A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC)…

Fix: 4.2+
Fix from $1,600 2020-01-26
Staros MEDIUM 5.9
CVE-2019-16026

A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an una…

Fix: 21.16.1+
Fix from $1,600 2020-01-26
Ios Xr MEDIUM 6.5
CVE-2019-16027

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in C…

Mitigation only
Fix from $1,600 2020-01-26
Collaboration Meeting Rooms HIGH 7.2
CVE-2019-16005

A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary co…

Fix: 2019.09.19.1956m+
Fix from $1,950 2020-01-26
Visual Studio 2017 HIGH 8.8
CVE-2019-1349EPSS 34%

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …

Fix: 15.9.18 / 16.4.1+
Fix from $1,950 2020-01-24
Visual Studio 2017 HIGH 8.8
CVE-2019-1350EPSS 26%

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …

Fix: 15.9.18 / 16.4.1+
Fix from $1,950 2020-01-24
Visual Studio 2017 HIGH 8.8
CVE-2019-1352EPSS 24%

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …

Fix: 15.9.18 / 16.4.1+
Fix from $1,950 2020-01-24