Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2020-14258 HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker… Notes Patch available Fix from $1,9502020-11-21 MEDIUM 6.6 CVE-2020-7842 Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection and execution when the time set… Wf2429tb Firmware Mitigation only Fix from $1,6002020-11-20 MEDIUM 5.3 CVE-2020-3441 A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information… Webex Meetings 3.0+ Fix from $1,6002020-11-18 CRITICAL 9.8 CVE-2020-3470 Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to exec… Enterprise Nfv Infrastructure Software 3.2.11.3 / 4.4.1+ Fix from $2,3002020-11-18 MEDIUM 6.5 CVE-2020-3471 A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional aud… Webex Meetings Server 3.0+ Fix from $1,6002020-11-18 HIGH 8.8 CVE-2020-7841 Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun… Xplatform 9.2.2.250+ Fix from $1,9502020-11-17 CRITICAL 9.8 CVE-2020-27131EPSS 88% Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker … Security Manager after 4.22 Fix from $2,3002020-11-17 CRITICAL 9.8 CVE-2020-27125 A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The … Security Manager after 4.21 Fix from $2,3002020-11-17 HIGH 8.8 CVE-2020-28648EPSS 6% Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code. Nagios Xi 5.7.5+ Fix from $1,9502020-11-16 HIGH 7.5 CVE-2020-25151 The affected product does not properly validate input, which may allow an attacker to execute a denial-of-service attack on the NIO 50 (all versions). Nio 50 Firmware No fix yet Fix from $1,9502020-11-13 MEDIUM 6.7 CVE-2020-9127 Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some ma… Nip6300 Firmware Mitigation only Fix from $1,6002020-11-13 MEDIUM 6.5 CVE-2020-8669 Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable info… Data Center Manager 3.6.2+ Fix from $1,6002020-11-12 HIGH 8.8 CVE-2020-12347 Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable esca… Data Center Manager 3.6.2+ Fix from $1,9502020-11-12 MEDIUM 6.5 CVE-2020-12349 Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable info… Data Center Manager 3.6.2+ Fix from $1,6002020-11-12 MEDIUM 6.7 CVE-2020-12323 Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of priv… Adas Ie 1.0.766+ Fix from $1,6002020-11-12 MEDIUM 6.7 CVE-2020-0572 Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable es… Server Board S2600st Firmware 02.01.0011 / 02.01.0012+ Fix from $1,6002020-11-12 MEDIUM 6.7 CVE-2020-8756 Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user… Converged Security And Manageability Engine 11.8.80 / 11.12.80+ Fix from $1,6002020-11-12 CRITICAL 9.8 CVE-2020-7472 An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9… Sugarcrm 8.0.7 / 9.0.4+ Fix from $2,3002020-11-12 MEDIUM 6.5 CVE-2020-12314 Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enabl… Proset\/wireless Wifi 21.110+ Fix from $1,6002020-11-12 MEDIUM 6.5 CVE-2020-12322 Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enab… Dual Band Wireless Ac 3168 Firmware 21.110+ Fix from $1,6002020-11-12 HIGH 7.8 CVE-2020-0590 Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege… Xeon Bronze 3206r Firmware Patch available Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-11201 Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapd… Qcm6125 Firmware No fix yet Fix from $1,9502020-11-12 HIGH 7.2 CVE-2020-2000 An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrup… Pan Os 8.1.16 / 9.0.10+ Fix from $1,9502020-11-12 MEDIUM 5.5 CVE-2020-16127 An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read … Accountsservice 0.6.55+ Fix from $1,6002020-11-11 HIGH 7.8 CVE-2020-26817 SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing … 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502020-11-10 HIGH 7.5 CVE-2020-0442 In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote de… Android Patch available Fix from $1,9502020-11-10 HIGH 7.5 CVE-2020-8268 Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the glob… Json8 Merge Patch 1.0.3+ Fix from $1,9502020-11-09 MEDIUM 6.5 CVE-2020-28349 An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malfo… Network Server Patch available Fix from $1,6002020-11-09 HIGH 7.5 CVE-2020-3444 A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic… Ios Xe after 17.2.1 Fix from $1,9502020-11-06 HIGH 7.3 CVE-2020-3556 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, loc… Anyconnect Secure Mobility Client Mitigation only Fix from $1,9502020-11-06