Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2020-28590 An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92a… Libslic3r No fix yet Fix from $1,6002021-04-13 MEDIUM 5.5 CVE-2021-0400 In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency se… Android Patch available Fix from $1,6002021-04-13 MEDIUM 6.5 CVE-2021-21393 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.28.0+ Fix from $1,6002021-04-12 MEDIUM 6.5 CVE-2021-21394 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.28.0+ Fix from $1,6002021-04-12 MEDIUM 5.3 CVE-2021-25378 Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service. Smartthings 1.7.63.6+ Fix from $1,6002021-04-09 HIGH 8.8 CVE-2021-25356 An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary a… Android No fix yet Fix from $1,9502021-04-09 HIGH 8.1 CVE-2021-21431 sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot usin… Channelmgnt 2.0.1+ Fix from $1,9502021-04-09 MEDIUM 6.5 CVE-2021-3482 A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetada… Enterprise Linux after 0.27.3 Fix from $1,6002021-04-08 HIGH 7.5 CVE-2021-1404 A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote att… Clamav Mitigation only Fix from $1,9502021-04-08 HIGH 7.5 CVE-2021-1252 A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated… Clamav Mitigation only Fix from $1,9502021-04-08 HIGH 7.8 CVE-2021-1480 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe… Catalyst Sd Wan Manager 19.2.4 / 20.3.3+ Fix from $1,9502021-04-08 CRITICAL 9.8 CVE-2021-1459 A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticate… Rv110w Firmware Mitigation only Fix from $2,3002021-04-08 HIGH 7.8 CVE-2021-1137 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe… Catalyst Sd Wan Manager 19.2.4 / 20.3.3+ Fix from $1,9502021-04-08 HIGH 7.8 CVE-2020-11237 Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in Snapdragon Auto, Sn… Csrb31024 Firmware Mitigation only Fix from $1,9502021-04-07 HIGH 7.5 CVE-2021-21404 Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and … Syncthing 1.15.0+ Fix from $1,9502021-04-06 MEDIUM 5.5 CVE-2021-29136 Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal whe… Umoci 0.4.7 / 3.7.3+ Fix from $1,6002021-04-06 MEDIUM 6.3 CVE-2021-21532 Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redir… Wyse Thinos 8.6+ Fix from $1,6002021-04-02 HIGH 8.8 CVE-2021-1748 A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4. Processin… Ipados 7.3 / 14.4+ Fix from $1,9502021-04-02 MEDIUM 5.5 CVE-2020-10001 An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, … Debian Linux 11.1.0+ Fix from $1,6002021-04-02 MEDIUM 5.3 CVE-2021-30004 In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c. Hostapd Patch available Fix from $1,6002021-04-02 HIGH 8.8 CVE-2021-22538 A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh… Exposure Notifications Verification Server 0.23.1+ Fix from $1,9502021-03-31 MEDIUM 5.3 CVE-2021-29418 The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in … Netmask 2.0.1+ Fix from $1,6002021-03-30 HIGH 7.5 CVE-2018-1110 A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service. Knot Resolver 2.3.0+ Fix from $1,9502021-03-30 HIGH 7.2 CVE-2021-20206 An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'ty… Container Network Interface 0.8.1+ Fix from $1,9502021-03-26 HIGH 8.8 CVE-2021-21372 Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ… Nim 1.2.10 / 1.4.4+ Fix from $1,9502021-03-26 MEDIUM 6.7 CVE-2021-1454 Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating s… Ios Xe Mitigation only Fix from $1,6002021-03-24 HIGH 7.2 CVE-2021-1469 Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execut… Jabber 12.1.5 / 12.5.4+ Fix from $1,9502021-03-24 HIGH 7.5 CVE-2021-1431 A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, r… Ios Xe Mitigation only Fix from $1,9502021-03-24 HIGH 7.3 CVE-2021-1432 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyi… Ios Xe Mitigation only Fix from $1,9502021-03-24 MEDIUM 6.7 CVE-2021-1383 Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating s… Ios Xe No fix yet Fix from $1,6002021-03-24