Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Visual Studio 2017 HIGH 8.8
CVE-2019-1354EPSS 22%

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution …

Fix: 15.9.18 / 16.4.1+
Fix from $1,950 2020-01-24
Android MEDIUM 5.5
CVE-2015-1525

audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted …

Fix: 5.1+
Fix from $1,600 2020-01-24
Tor HIGH 7.5
CVE-2015-2689

Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which all…

Fix: 0.2.4.26 / 0.2.5.11+
Fix from $1,950 2020-01-24
Apexpro Telemetry Server Firmware CRITICAL 9.9
CVE-2020-6965

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, …

Fix: after 4.2
Fix from $2,300 2020-01-24
Apexpro Telemetry Server Firmware CRITICAL 10.0
CVE-2020-6962

In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X,…

Fix: after 4.2
Fix from $2,300 2020-01-24
Apexpro Telemetry Server Firmware CRITICAL 10.0
CVE-2020-6963

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, …

Fix: after 4.2
Fix from $2,300 2020-01-24
Babygekko CRITICAL 9.8
CVE-2012-5699

BabyGekko before 1.2.4 allows PHP file inclusion.

Fix: 1.2.4+
Fix from $2,300 2020-01-23
Unleashed CRITICAL 9.8
CVE-2019-19836

AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rc…

Fix: 9.10.2.0.84 / 9.12.3.0.136+
Fix from $2,300 2020-01-22
Usebb HIGH 7.2
CVE-2011-3611

A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

Fix: 1.0.12+
Fix from $1,950 2020-01-22
Grin HIGH 7.5
CVE-2020-6638

Grin through 2.1.1 has Insufficient Validation.

Fix: after 2.1.1
Fix from $1,950 2020-01-21
Papercrop CRITICAL 9.8
CVE-2015-2784

The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.

Fix: 0.3.0+
Fix from $2,300 2020-01-21
Mdm9607 Firmware HIGH 7.5
CVE-2019-14010

The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd buffer map which happens to b…

Patch available
Fix from $1,950 2020-01-21
Enterprise Linux HIGH 8.3
CVE-2019-9503

The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfma…

Patch available
Fix from $1,950 2020-01-16
Superdome Flex Server Firmware MEDIUM 5.5
CVE-2019-11998

HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerabilit…

Fix: 3.20.186+
Fix from $1,600 2020-01-16
Rx3i Cpe100 Firmware HIGH 7.5
CVE-2019-13524

GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) …

Patch available
Fix from $1,950 2020-01-16
Capital Vstar HIGH 7.1
CVE-2019-13939

A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE P…

Fix: 2.8.2 / 2017.02.2+
Fix from $1,950 2020-01-16
Email Security Appliance Firmware MEDIUM 6.5
CVE-2019-15961

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remo…

Fix: after 0.101.4
Fix from $1,600 2020-01-15
Debian Linux HIGH 7.5
CVE-2015-5230EPSS 9%

The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of se…

Fix: 3.4.6+
Fix from $1,950 2020-01-15
Ironport Web Security Appliance HIGH 7.4
CVE-2012-1326

Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead t…

Fix: after 7.5
Fix from $1,950 2020-01-15
Ironport Web Security Appliance MEDIUM 6.4
CVE-2012-0334

Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle a…

Fix: 7.5+
Fix from $1,600 2020-01-15
Cacti HIGH 8.8
CVE-2020-7058

data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. …

No fix yet
Fix from $1,950 2020-01-15
Windows 10 MEDIUM 6.0
CVE-2020-0617

A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user …

Patch available
Fix from $1,600 2020-01-14
.net Framework HIGH 8.8
CVE-2020-0605EPSS 17%

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successful…

Patch available
Fix from $1,950 2020-01-14
.net Framework HIGH 8.8
CVE-2020-0606EPSS 16%

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successful…

Patch available
Fix from $1,950 2020-01-14
Nginx Ingress Controller MEDIUM 5.3
CVE-2018-1002104

Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.

Fix: 1.5.0+
Fix from $1,600 2020-01-14
Jcow Cms CRITICAL 9.8
CVE-2011-3203

A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.

Fix: after 5.2
Fix from $2,300 2020-01-14
Netweaver Internet Communication Manager \(kernel\) HIGH 7.5
CVE-2020-6304

Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL6…

Mitigation only
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool HIGH 7.1
CVE-2015-3150

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory ar…

Patch available
Fix from $1,950 2020-01-14
Wps Office HIGH 8.1
CVE-2014-2271

cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP…

Mitigation only
Fix from $1,950 2020-01-14
Receiver HIGH 7.8
CVE-2012-4603EPSS 7%

Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute ar…

Fix: after 12.1
Fix from $1,950 2020-01-10