Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2020-14956 In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified … Windows Cleanup Assistant Mitigation only Fix from $1,9502020-06-30 HIGH 7.8 CVE-2020-14957 In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified … Windows Cleanup Assistant Mitigation only Fix from $1,9502020-06-30 HIGH 8.8 CVE-2019-19163 A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbitrary code, because of a usin… Cdp 1020mb Firmware after 2019.12.30 Fix from $1,9502020-06-30 MEDIUM 6.5 CVE-2020-3767 ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability. Successful exploitation could lead to a… Coldfusion Mitigation only Fix from $1,6002020-06-26 MEDIUM 5.5 CVE-2020-14955 In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified oth… Jiangmin Antivirus No fix yet Fix from $1,6002020-06-26 HIGH 8.8 CVE-2020-12033 In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers… Factorytalk Services Platform Mitigation only Fix from $1,9502020-06-23 HIGH 7.8 CVE-2020-14939 An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A … Freedroidrpg No fix yet Fix from $1,9502020-06-23 MEDIUM 5.4 CVE-2020-1727 A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it al… Keycloak 9.0.2+ Fix from $1,6002020-06-22 HIGH 7.2 CVE-2019-14894 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu… Cloudforms Management Engine Mitigation only Fix from $1,9502020-06-22 HIGH 8.8 CVE-2020-8102 Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web… Total Security 2020 24.0.20.116+ Fix from $1,9502020-06-22 HIGH 7.8 CVE-2020-3676 Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consume… Apq8096au Firmware Mitigation only Fix from $1,9502020-06-22 MEDIUM 5.5 CVE-2019-10626 Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage data in Snapdragon Auto, Snapdr… Apq8009 Firmware Mitigation only Fix from $1,6002020-06-22 HIGH 7.8 CVE-2019-14047 While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Sn… Apq8053 Firmware Mitigation only Fix from $1,9502020-06-22 MEDIUM 5.3 CVE-2016-11067 An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang. Mattermost Server 3.2.0+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18873 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) … Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2018-21264 An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a SAML response. Mattermost Server 4.5.2 / 4.6.2+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-8184 A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an… Debian Linux 2.1.4 / 2.2.3+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-13961 Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are stored in a global variable wit… Strapi 3.0.2+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2018-21262 An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application crash) via invalid LaTeX tex… Mattermost Server 4.7.3+ Fix from $1,9502020-06-19 MEDIUM 5.3 CVE-2018-21259 An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via… Mattermost Server 4.8.2 / 4.9.4+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2019-20868 An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. Mattermost Server 4.10.8 / 5.7.3+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2020-14459 An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a direct message, aka MMSA-2020… Mattermost Server 5.19.0+ Fix from $1,9502020-06-19 HIGH 7.5 CVE-2019-20848 An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies. Mattermost Mobile 1.26.0+ Fix from $1,9502020-06-19 MEDIUM 5.8 CVE-2020-3368 A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat… Asyncos 13.5.0+ Fix from $1,6002020-06-18 MEDIUM 5.3 CVE-2020-3244 A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthentic… Staros 21.18.0+ Fix from $1,6002020-06-18 HIGH 7.5 CVE-2020-3263 A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user syste… Webex Meetings 39.5.12+ Fix from $1,9502020-06-18 MEDIUM 5.3 CVE-2020-7504 A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable … Easergy T300 Firmware after 1.5.2 Fix from $1,6002020-06-16 HIGH 7.5 CVE-2020-8543 OX App Suite through 7.10.3 has Improper Input Validation. Open Xchange Appsuite No fix yet Fix from $1,9502020-06-16 HIGH 8.1 CVE-2020-11999 FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:… Factorytalk Linx after 4.11.00 Fix from $1,9502020-06-15 CRITICAL 9.8 CVE-2020-12001EPSS 12% FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:… Factorytalk Linx after 4.11.00 Fix from $2,3002020-06-15