Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2020-7454 In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias … FreeBSD Mitigation only Fix from $2,3002020-05-13 CRITICAL 9.8 CVE-2019-15880 In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffe… FreeBSD Mitigation only Fix from $2,3002020-05-13 MEDIUM 6.1 CVE-2020-12742 The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols. Iubenda Cookie Law Solution 2.3.5+ Fix from $1,6002020-05-13 HIGH 7.5 CVE-2020-3327EPSS 5% A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacke… Clam Antivirus after 0.102.2 Fix from $1,9502020-05-13 HIGH 7.5 CVE-2020-3341 A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote… Clam Antivirus after 0.102.2 Fix from $1,9502020-05-13 HIGH 7.2 CVE-2020-6248 SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while execut… Adaptive Server Enterprise Backup Server Mitigation only Fix from $1,9502020-05-12 HIGH 7.8 CVE-2020-10028 Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versio… Zephyr Patch available Fix from $1,9502020-05-11 HIGH 7.8 CVE-2020-10058 Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated … Zephyr Patch available Fix from $1,9502020-05-11 HIGH 7.5 CVE-2020-12752 An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a bru… Android Mitigation only Fix from $1,9502020-05-11 HIGH 7.8 CVE-2018-20225 An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtai… Pip Mitigation only Fix from $1,9502020-05-08 HIGH 8.8 CVE-2019-19164 dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by set… Dext5 Mitigation only Fix from $1,9502020-05-07 HIGH 8.8 CVE-2020-10971 An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the sup… Wl Wn575a3 Firmware Mitigation only Fix from $1,9502020-05-07 HIGH 8.8 CVE-2020-7803 IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.o… Zoneplayer Mitigation only Fix from $1,9502020-05-07 HIGH 7.3 CVE-2020-6651 Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allow… Intelligent Power Manager after 1.67 Fix from $1,9502020-05-07 MEDIUM 5.3 CVE-2018-8956 ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadc… Ntp Mitigation only Fix from $1,6002020-05-06 HIGH 8.8 CVE-2020-12669 core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric me… Dolibarr 11.0.4+ Fix from $1,9502020-05-06 HIGH 8.1 CVE-2020-3302 A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on… Secure Firewall Management Center 6.2.2.2+ Fix from $1,9502020-05-06 MEDIUM 5.3 CVE-2020-3307 A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary … Secure Firewall Management Center Mitigation only Fix from $1,6002020-05-06 HIGH 7.2 CVE-2020-3309 A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to overwrite arbitrary files on… Firepower Device Manager On Box 6.2.3+ Fix from $1,9502020-05-06 HIGH 8.6 CVE-2020-3191 A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software c… Secure Firewall Threat Defense 6.2.3.16 / 6.3.0.6+ Fix from $1,9502020-05-06 MEDIUM 5.3 CVE-2020-10693 A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evalua… Hibernate Validator 6.0.20 / 6.1.5+ Fix from $1,6002020-05-06 MEDIUM 6.8 CVE-2017-18867 Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55, D7800 before V1.0.1.24, R71… D6100 Firmware 1.0.0.32 / 1.0.0.48+ Fix from $1,6002020-05-05 HIGH 7.8 CVE-2020-10622 LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users Laquis Scada after 4.3.1 Fix from $1,9502020-05-04 HIGH 7.8 CVE-2019-16011 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are execute… Ios Xe 17.2.1r+ Fix from $1,9502020-04-29 HIGH 7.5 CVE-2020-8475 For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co… 800xa System Mitigation only Fix from $1,9502020-04-29 HIGH 7.5 CVE-2020-8476 For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co… 800xa System Mitigation only Fix from $1,9502020-04-29 CRITICAL 9.8 CVE-2019-15874 In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, inco… FreeBSD Patch available Fix from $2,3002020-04-29 CRITICAL 9.8 CVE-2019-5614 In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, inco… FreeBSD Patch available Fix from $2,3002020-04-29 HIGH 7.5 CVE-2020-10663EPSS 7% The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulne… Json after 2.2.0 Fix from $1,9502020-04-28 MEDIUM 5.3 CVE-2019-5302 There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue bas… Alp Al00b Firmware 9.1.0.300 / 9.1.0.302+ Fix from $1,6002020-04-27