Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2020-3317 A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to c… Secure Firewall Threat Defense 6.4.0.10 / 6.5.0.5+ Fix from $1,9502020-10-21 MEDIUM 6.5 CVE-2020-6366 SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administra… Netweaver Compare Systems Mitigation only Fix from $1,6002020-10-20 CRITICAL 9.8 CVE-2020-15256 A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `incl… Object Path 0.11.5+ Fix from $2,3002020-10-19 HIGH 7.5 CVE-2020-24388 An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field o… Fedora after 2.0.2 Fix from $1,9502020-10-19 MEDIUM 6.7 CVE-2020-11496 Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks … Sprecon E 8.64b+ Fix from $1,6002020-10-19 CRITICAL 9.8 CVE-2020-24649 A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)… Intelligent Management Center 7.3+ Fix from $2,3002020-10-19 CRITICAL 9.8 CVE-2020-24647 A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s… Intelligent Management Center 7.3+ Fix from $2,3002020-10-19 HIGH 7.8 CVE-2020-1167 <p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully … Windows 10 Patch available Fix from $1,9502020-10-16 HIGH 7.8 CVE-2020-16968 <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully… Windows 10 Patch available Fix from $1,9502020-10-16 HIGH 8.8 CVE-2020-16891 <p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on … Windows 10 Patch available Fix from $1,9502020-10-16 HIGH 7.5 CVE-2020-1672 On Juniper Networks Junos OS devices configured with DHCPv6 relay enabled, receipt of a specific DHCPv6 packet might crash the jdhcpd daemon. The jdh… Junos Mitigation only Fix from $1,9502020-10-16 HIGH 7.2 CVE-2020-1676 When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a v… Mist Cloud Ui 2020-09-02+ Fix from $1,9502020-10-16 HIGH 7.2 CVE-2020-1677 When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote atta… Mist Cloud Ui 2020-09-02+ Fix from $1,9502020-10-16 HIGH 7.5 CVE-2020-1679 On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet… Junos Mitigation only Fix from $1,9502020-10-16 MEDIUM 5.5 CVE-2020-1682 An input validation vulnerability exists in Juniper Networks Junos OS, allowing an attacker to crash the srxpfe process, causing a Denial of Service … Junos Mitigation only Fix from $1,6002020-10-16 HIGH 8.8 CVE-2020-1656 The DHCPv6 Relay-Agent service, part of the Juniper Enhanced jdhcpd daemon shipped with Juniper Networks Junos OS has an Improper Input Validation vu… Junos Mitigation only Fix from $1,9502020-10-16 HIGH 7.5 CVE-2020-1662 On Juniper Networks Junos OS and Junos OS Evolved devices, BGP session flapping can lead to a routing process daemon (RPD) crash and restart, limitin… Junos Mitigation only Fix from $1,9502020-10-16 HIGH 7.5 CVE-2020-9931 A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may cause … Ipados 13.6+ Fix from $1,9502020-10-16 HIGH 7.5 CVE-2020-9914 An input validation issue existed in Bluetooth. This issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 1… Ipados 13.4.8 / 13.6+ Fix from $1,9502020-10-16 HIGH 8.8 CVE-2020-9870 A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attack… Ipados 10.15.6 / 13.4.8+ Fix from $1,9502020-10-16 HIGH 8.0 CVE-2020-15258 In Wire before 3.20.x, `shell.openExternal` was used without checking the URL. This vulnerability allows an attacker to execute code on the victims m… Wire 3.20.2934+ Fix from $1,9502020-10-16 HIGH 7.8 CVE-2020-6372 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502020-10-15 HIGH 7.8 CVE-2020-6373 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502020-10-15 HIGH 7.8 CVE-2020-6374 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which … 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502020-10-15 MEDIUM 5.5 CVE-2020-6375 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted … 3d Visual Enterprise Viewer Mitigation only Fix from $1,6002020-10-15 MEDIUM 5.5 CVE-2020-6376 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources wh… 3d Visual Enterprise Viewer Mitigation only Fix from $1,6002020-10-15 CRITICAL 9.8 CVE-2020-8349 An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ option… Cloud Networking Operating System 10.10.6.0+ Fix from $2,3002020-10-14 MEDIUM 5.5 CVE-2020-6933 An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and ear… Unified Endpoint Manager after 12.11.1 Fix from $1,6002020-10-14 MEDIUM 6.5 CVE-2020-9122 Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in the LAN to cause service abno… Hirouter Cd30 10 Firmware 10.0.2.37 / 10.0.3.33+ Fix from $1,6002020-10-12 MEDIUM 6.5 CVE-2020-4781 An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could resul… Curam Social Program Management Mitigation only Fix from $1,6002020-10-12