Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2016-9021 Exponent CMS before 2.6.0 has improper input validation in storeController.php. Exponent Cms 2.6.0+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2016-9022 Exponent CMS before 2.6.0 has improper input validation in usersController.php. Exponent Cms 2.6.0+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2016-9023 Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php. Exponent Cms 2.6.0+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2016-9025 Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php. Exponent Cms 2.6.0+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2016-9026 Exponent CMS before 2.6.0 has improper input validation in fileController.php. Exponent Cms 2.6.0+ Fix from $2,3002020-12-31 MEDIUM 6.5 CVE-2020-26291 URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`… Uri.js 1.19.4+ Fix from $1,6002020-12-31 HIGH 8.8 CVE-2020-35789 NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user. Nms300 Firmware 1.6.0.27+ Fix from $1,9502020-12-30 HIGH 7.5 CVE-2020-35616EPSS 6% An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations. Joomla\! after 3.9.22 Fix from $1,9502020-12-28 HIGH 7.5 CVE-2020-14273 HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated at… Domino No fix yet Fix from $1,9502020-12-28 MEDIUM 6.7 CVE-2020-9137 There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to in… Cloudengine 12800 Firmware Mitigation only Fix from $1,6002020-12-24 HIGH 7.5 CVE-2020-2504 If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues… Qes 2.1.1+ Fix from $1,9502020-12-24 HIGH 7.1 CVE-2020-27338 An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows an unauthenticated remote atta… Ipv6 6.0.1.68+ Fix from $1,9502020-12-22 CRITICAL 9.8 CVE-2020-24679 A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even ex… Symphony \+ Historian Mitigation only Fix from $2,3002020-12-22 MEDIUM 5.3 CVE-2020-27336 An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthentica… Ipv6 6.0.1.68+ Fix from $1,6002020-12-22 HIGH 7.3 CVE-2020-27337 An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to c… Ipv6 6.0.1.68+ Fix from $1,9502020-12-22 HIGH 8.8 CVE-2020-14231 A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resul… Hcl Client Application Access Mitigation only Fix from $1,9502020-12-22 HIGH 8.8 CVE-2019-11781 Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to tri… Odoo after 12.0 Fix from $1,9502020-12-22 CRITICAL 9.1 CVE-2018-15632 Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers… Odoo after 11.0 Fix from $2,3002020-12-22 HIGH 7.5 CVE-2020-35623 An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation wit… Mediawiki after 1.35.1 Fix from $1,9502020-12-21 MEDIUM 6.5 CVE-2020-3999 VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 an… Workstation 11.5.7 / 15.5.7+ Fix from $1,6002020-12-21 HIGH 8.8 CVE-2020-27687 ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-… Thingsboard 3.2+ Fix from $1,9502020-12-18 MEDIUM 6.1 CVE-2020-25606 The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input val… Micollab 9.2+ Fix from $1,6002020-12-18 HIGH 7.2 CVE-2020-25608 The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection. Micollab 9.2+ Fix from $1,9502020-12-18 MEDIUM 6.1 CVE-2020-25611 The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to imprope… Micollab 9.2+ Fix from $1,6002020-12-18 HIGH 8.8 CVE-2020-27154 The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access … Businesscti Enterprise 6.4.11 / 7.0.3+ Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-7838 A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrar… Stove after 0.0.4.71 Fix from $1,9502020-12-18 MEDIUM 6.5 CVE-2020-12521 On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET … Plcnext Firmware 2021.0+ Fix from $1,6002020-12-17 MEDIUM 5.5 CVE-2020-15292 Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTa… Hypervisor Introspection 1.132.2+ Fix from $1,6002020-12-17 MEDIUM 5.5 CVE-2020-15293 Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input va… Hypervisor Introspection Mitigation only Fix from $1,6002020-12-17 HIGH 7.5 CVE-2020-5682 Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and ear… Growi 4.1.12 / 4.2.3+ Fix from $1,9502020-12-16