Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2020-25757 A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command API… Dsr 150 Firmware after 3.17 Fix from $1,9502020-12-15 HIGH 8.8 CVE-2020-25759 An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticat… Dsr 150 Firmware after 3.17 Fix from $1,9502020-12-15 HIGH 7.5 CVE-2020-25195 The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving… H0 Ecom100 Firmware after 5.0.1043 Fix from $1,9502020-12-15 MEDIUM 6.5 CVE-2020-27029 In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no addi… Android Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.5 CVE-2020-0493 In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to loca… Android Mitigation only Fix from $1,6002020-12-15 HIGH 7.5 CVE-2020-17444 An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid… Picotcp after 1.7.0 Fix from $1,9502020-12-11 HIGH 8.3 CVE-2020-17439 An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the i… Uip Mitigation only Fix from $1,9502020-12-11 MEDIUM 6.7 CVE-2020-15375 Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the comman… Fabric Operating System 7.4.2g / 8.1.2k+ Fix from $1,6002020-12-11 HIGH 8.8 CVE-2020-4633 IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input val… Resilient Security Orchestration Automation And Response Mitigation only Fix from $1,9502020-12-11 HIGH 7.8 CVE-2020-27828 There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-b… Fedora 2.0.23+ Fix from $1,9502020-12-11 MEDIUM 6.5 CVE-2020-26409 A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource b… GitLab 13.4.7 / 13.5.5+ Fix from $1,6002020-12-11 HIGH 7.8 CVE-2020-27614 AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local… Anydesk after 6.0.2 Fix from $1,9502020-12-09 MEDIUM 5.5 CVE-2020-9977 A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue … Ipados 11.0.1 / 14.2+ Fix from $1,6002020-12-08 HIGH 7.5 CVE-2020-5680 Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) conditio… Ec Cube after 3.0.18 Fix from $1,9502020-12-03 HIGH 7.2 CVE-2020-9115 ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An … Manageone Mitigation only Fix from $1,9502020-12-01 HIGH 7.5 CVE-2020-16850 Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over… R00cpu Firmware after 52 Fix from $1,9502020-11-30 HIGH 7.5 CVE-2020-27253 A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticat… Factorytalk Linx after 6.11 Fix from $1,9502020-11-26 HIGH 7.5 CVE-2020-26243 Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can le… Nanopb 0.3.9.7 / 0.4.4+ Fix from $1,9502020-11-25 CRITICAL 9.8 CVE-2020-13942EPSS 68% It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve… Unomi 1.5.2+ Fix from $2,3002020-11-24 HIGH 7.5 CVE-2020-26890 Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing re… Fedora 1.20.0+ Fix from $1,9502020-11-24 HIGH 7.8 CVE-2018-16719 In Jingyun Antivirus v2.4.2.39, the driver file (hookbody.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified ot… Jingyun Antivirus No fix yet Fix from $1,9502020-11-23 HIGH 7.8 CVE-2018-16720 In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o… Jingyun Antivirus No fix yet Fix from $1,9502020-11-23 HIGH 7.8 CVE-2018-16721 In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o… Jingyun Antivirus No fix yet Fix from $1,9502020-11-23 HIGH 7.8 CVE-2018-16722 In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o… Jingyun Antivirus No fix yet Fix from $1,9502020-11-23 HIGH 7.8 CVE-2018-16723 In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified o… Jingyun Antivirus No fix yet Fix from $1,9502020-11-23 HIGH 8.8 CVE-2020-12351EPSS 8% Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. Linux Kernel 4.9.240 / 4.14.202+ Fix from $1,9502020-11-23 MEDIUM 6.5 CVE-2018-20804 A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects Mon… MongoDB 3.6.13 / 4.0.10+ Fix from $1,6002020-11-23 HIGH 7.5 CVE-2020-7925 Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a spec… MongoDB 4.2.9+ Fix from $1,9502020-11-23 HIGH 7.5 CVE-2020-14230 HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacke… Domino 9.0.1 / 10.0.1+ Fix from $1,9502020-11-21 HIGH 7.5 CVE-2020-14234 HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the … Domino 9.0.1 / 10.0.1+ Fix from $1,9502020-11-21