Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2020-3248EPSS 74% Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth… Ucs Director after 3.7.3.0 Fix from $2,3002020-04-15 HIGH 7.5 CVE-2020-3249EPSS 23% Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth… Ucs Director after 3.7.3.0 Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2020-3250EPSS 60% Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth… Ucs Director after 3.7.3.0 Fix from $2,3002020-04-15 HIGH 8.8 CVE-2020-3251EPSS 62% Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth… Ucs Director after 3.7.3.0 Fix from $1,9502020-04-15 MEDIUM 6.5 CVE-2020-3252EPSS 5% Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth… Ucs Director after 3.7.3.0 Fix from $1,6002020-04-15 CRITICAL 9.8 CVE-2020-3161 KEVEPSS 84% A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a… Ip Phone 8865 Firmware Mitigation only Fix from $2,3002020-04-15 HIGH 7.5 CVE-2019-12520 An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does th… Ubuntu Linux after 4.7 Fix from $1,9502020-04-15 MEDIUM 6.1 CVE-2020-3954 Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. Vrealize Log Insight 8.1.0+ Fix from $1,6002020-04-15 CRITICAL 9.8 CVE-2020-11534 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function … Document Server Mitigation only Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-11536 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite … Document Server Mitigation only Fix from $2,3002020-04-15 HIGH 7.8 CVE-2020-0984 An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing … Autoupdate Patch available Fix from $1,9502020-04-15 HIGH 8.4 CVE-2020-0910EPSS 9% A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g… Windows 10 Patch available Fix from $1,9502020-04-15 HIGH 8.2 CVE-2020-2908 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4… Vm Virtualbox 5.2.40 / 6.0.20+ Fix from $1,9502020-04-15 HIGH 7.5 CVE-2020-2907 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4… Vm Virtualbox 5.2.40 / 6.0.20+ Fix from $1,9502020-04-15 HIGH 7.5 CVE-2020-5260EPSS 10% Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us… Git 2.17.4 / 2.18.3+ Fix from $1,9502020-04-14 MEDIUM 5.5 CVE-2020-8324 A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow uns… System Interface Foundation 1.2.184.31+ Fix from $1,6002020-04-14 HIGH 7.5 CVE-2020-6227 SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to s… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502020-04-14 MEDIUM 6.5 CVE-2020-4151 IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-For… Qradar Security Information And Event Manager after 7.3.3 Fix from $1,6002020-04-14 MEDIUM 6.5 CVE-2020-1633 Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Br… Junos Mitigation only Fix from $1,6002020-04-09 MEDIUM 6.7 CVE-2020-1619 A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Next-Generation Routing Engine … Junos Mitigation only Fix from $1,6002020-04-08 HIGH 7.8 CVE-2020-1984 Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access t… Secdo Mitigation only Fix from $1,9502020-04-08 MEDIUM 5.5 CVE-2020-1986 Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS… Secdo Mitigation only Fix from $1,6002020-04-08 MEDIUM 6.2 CVE-2018-21068 An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a pas… Android Mitigation only Fix from $1,6002020-04-08 HIGH 7.5 CVE-2018-21078 An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate vi… Android Mitigation only Fix from $1,9502020-04-08 CRITICAL 9.8 CVE-2018-21055 An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software. A device can be rooted with a custom… Android Mitigation only Fix from $2,3002020-04-08 MEDIUM 6.5 CVE-2018-21092 An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via… Android Mitigation only Fix from $1,6002020-04-08 HIGH 7.1 CVE-2015-9544 An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any vali… Cross Domain Local Storage after 2.0.5 Fix from $1,9502020-04-07 HIGH 7.1 CVE-2015-9545 An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the … Cross Domain Local Storage after 2.0.5 Fix from $1,9502020-04-07 CRITICAL 9.8 CVE-2017-18683 An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows Hare Hunting during application installation. Th… Android No fix yet Fix from $2,3002020-04-07 CRITICAL 9.8 CVE-2017-18684 An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows provider seizure via an application that uses a … Android Mitigation only Fix from $2,3002020-04-07