Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.4 CVE-2021-34714 A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR S… Fxos 2.2.2.148 / 2.3.1.216+ Fix from $1,9502021-09-23 HIGH 7.1 CVE-2021-3583 A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i… Ansible Automation Platform 2.9.23 / 3.7.0+ Fix from $1,9502021-09-22 MEDIUM 6.5 CVE-2021-39230 Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are recommend to update to the Trin… Butter 1.5+ Fix from $1,6002021-09-21 HIGH 7.5 CVE-2021-41531 NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This wil… Routinator 0.10.0+ Fix from $1,9502021-09-21 HIGH 8.1 CVE-2021-25741EPSS 8% A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories… Kubernetes after 1.22.1 Fix from $1,9502021-09-20 MEDIUM 6.5 CVE-2021-41380 RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserte… Vnc Viewer No fix yet Fix from $1,6002021-09-17 HIGH 7.5 CVE-2020-12080 A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited… Flexnet Publisher No fix yet Fix from $1,9502021-09-17 HIGH 7.8 CVE-2021-38304 Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable es… Ni Pal after 20.0.0 Fix from $1,9502021-09-17 HIGH 7.8 CVE-2021-30260 Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration comma… Apq8009 Firmware Mitigation only Fix from $1,9502021-09-17 HIGH 7.8 CVE-2021-30261 Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon… Apq8009 Firmware Mitigation only Fix from $1,9502021-09-17 HIGH 7.5 CVE-2021-41079EPSS 7% Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured … Tomcat 8.5.64 / 9.0.44+ Fix from $1,9502021-09-16 CRITICAL 9.8 CVE-2021-37909 WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permis… Tssservisignadapter after 1.0.20.0316 Fix from $2,3002021-09-15 HIGH 7.5 CVE-2021-23028 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configure… Big Ip Advanced Web Application Firewall 15.1.3.1+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23030 On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all… Big Ip Advanced Web Application Firewall after 16.0.1.1 Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23036 On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traf… Big Ip Advanced Web Application Firewall after 16.0.1 Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23032 On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is con… Big Ip Domain Name System 14.1.4.4 / 15.1.3.1+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23033 On BIG-IP Advanced WAF and BIG-IP ASM version 16.x before 16.1.0x, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all ve… Big Ip Advanced Web Application Firewall 13.1.4.1 / 14.1.4.3+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23034 On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, und… Big Ip Access Policy Manager 15.1.3.1 / 16.1.0+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23035 On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can… Big Ip Access Policy Manager after 14.1.4.4 Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23039 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a… Big Ip Access Policy Manager 14.1.2.8 / 15.1.3+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23045 On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an… Big Ip Access Policy Manager 13.1.4.1 / 14.1.4.3+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23044 On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, … Big Ip Access Policy Manager 13.1.4.1 / 14.1.4.2+ Fix from $1,9502021-09-14 MEDIUM 5.3 CVE-2021-20569 IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243. Security Secret Server 11.0+ Fix from $1,6002021-09-14 HIGH 7.5 CVE-2021-23051 On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Am… Big Ip Access Policy Manager 15.1.3.1+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-23048 On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6… Big Ip Access Policy Manager 13.1.4.1 / 14.1.4.3+ Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-37206 A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (A… Siprotec 5 With Cpu Variant Cp050 8.80+ Fix from $1,9502021-09-14 HIGH 7.0 CVE-2021-25465 An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack. Themes 5.2.01+ Fix from $1,9502021-09-09 MEDIUM 5.5 CVE-2021-25453 Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information. Android Mitigation only Fix from $1,6002021-09-09 MEDIUM 6.5 CVE-2021-25450 Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socke… Android Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.5 CVE-2021-25452 An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent … Android Mitigation only Fix from $1,6002021-09-09