Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2017-18685 An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash… Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2017-18674 An issue was discovered on Samsung mobile devices with N(7.0) software. The time service (aka Timaservice) allows a kernel panic. The Samsung ID is S… Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2017-18676 An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm chipsets) software. There is an RKP kernel protection bypass (in which unwant… Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2017-18679 An issue was discovered on Samsung mobile devices with M(6.0) software. SLocation can cause a system crash via a call to an API that is not implement… Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.1 CVE-2017-18680 An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interface allows Add User actions, le… Android Mitigation only Fix from $1,9502020-04-07 CRITICAL 9.1 CVE-2017-18648 An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file read/write operations can occur… Android Mitigation only Fix from $2,3002020-04-07 CRITICAL 9.8 CVE-2020-7614 npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validatio… Npm Programmatic after 0.0.12 Fix from $2,3002020-04-07 HIGH 7.5 CVE-2016-11031 An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. … Android Mitigation only Fix from $1,9502020-04-07 MEDIUM 5.3 CVE-2016-11032 An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotecte… Android Mitigation only Fix from $1,6002020-04-07 HIGH 7.8 CVE-2016-11052 An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a … Android Mitigation only Fix from $1,9502020-04-07 HIGH 7.5 CVE-2016-11046 An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reac… Android Mitigation only Fix from $1,9502020-04-07 CRITICAL 9.8 CVE-2020-8147 Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code ex… Utils Extend after 1.0.8 Fix from $2,3002020-04-03 MEDIUM 5.4 CVE-2019-19095 Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by… Esoms after 6.0.2 Fix from $1,6002020-04-02 HIGH 8.8 CVE-2018-13371 An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via conn… Fortios after 6.0.2 Fix from $1,9502020-04-02 HIGH 7.2 CVE-2020-10204EPSS 38% Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. Nexus 3.21.2+ Fix from $1,9502020-04-01 CRITICAL 9.8 CVE-2020-3847 An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to l… Mac Os X 10.15.3+ Fix from $2,3002020-04-01 CRITICAL 9.8 CVE-2020-3848 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able … Mac Os X 10.15.3+ Fix from $2,3002020-04-01 CRITICAL 9.8 CVE-2020-3849 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able … Mac Os X 10.15.3+ Fix from $2,3002020-04-01 CRITICAL 9.8 CVE-2020-3850 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able … Mac Os X 10.15.3+ Fix from $2,3002020-04-01 HIGH 7.8 CVE-2020-3892 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be… Mac Os X 10.15.4+ Fix from $1,9502020-04-01 HIGH 7.8 CVE-2020-3893 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be… Mac Os X 10.15.4+ Fix from $1,9502020-04-01 HIGH 7.8 CVE-2020-3905 A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be… Mac Os X 10.15.4+ Fix from $1,9502020-04-01 MEDIUM 6.1 CVE-2020-3884 An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbi… Mac Os X 10.15.4+ Fix from $1,6002020-04-01 MEDIUM 5.6 CVE-2019-14905 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos… Ansible Engine 2.7.16 / 2.8.8+ Fix from $1,6002020-03-31 HIGH 7.5 CVE-2020-4214 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-s… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-4206 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user… Spectrum Protect Plus after 10.1.5 Fix from $1,9502020-03-31 CRITICAL 9.8 CVE-2020-10374 A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST req… Prtg Network Monitor after 20.1.56 Fix from $2,3002020-03-30 CRITICAL 9.8 CVE-2020-10885EPSS 7% This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route… Ac1750 Firmware Mitigation only Fix from $2,3002020-03-25 HIGH 8.8 CVE-2020-2166 Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in … Pipeline\ after 1.40 Fix from $1,9502020-03-25 HIGH 8.8 CVE-2020-2167 Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in… Openshift Pipeline after 1.0.56 Fix from $1,9502020-03-25