Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2020-2168 Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resultin… Azure Container Service after 1.0.1 Fix from $1,9502020-03-25 CRITICAL 9.1 CVE-2020-5555 Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is pl… Shihonkanri Plus Goout Mitigation only Fix from $2,3002020-03-25 HIGH 7.8 CVE-2019-4001 Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code. Insync No fix yet Fix from $1,9502020-03-24 CRITICAL 9.8 CVE-2020-10837 An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and a… Android Mitigation only Fix from $2,3002020-03-24 CRITICAL 9.8 CVE-2020-1747EPSS 5% A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes … Fedora 5.3.1+ Fix from $2,3002020-03-24 MEDIUM 5.4 CVE-2020-6425 Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious… Chrome 80.0.3987.149+ Fix from $1,6002020-03-23 HIGH 7.5 CVE-2018-20335 An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= … Asuswrt No fix yet Fix from $1,9502020-03-20 HIGH 7.8 CVE-2020-10648 Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT im… U Boot 2018.03+ Fix from $1,9502020-03-19 MEDIUM 5.7 CVE-2019-20485 qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a… Libvirt 6.0.0+ Fix from $1,6002020-03-19 HIGH 7.5 CVE-2020-8787 SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted. Suitecrm 7.10.23 / 7.11.11+ Fix from $1,9502020-03-16 HIGH 7.5 CVE-2017-12842 Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that pa… Bitcoin Core 0.14.0+ Fix from $1,9502020-03-16 MEDIUM 5.3 CVE-2020-10240 An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames … Joomla\! 3.9.16+ Fix from $1,6002020-03-16 HIGH 7.5 CVE-2019-19942 Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 b… Centro Grande Firmware 6.14.06 / 7.10.18+ Fix from $1,9502020-03-16 MEDIUM 6.1 CVE-2019-6696 An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an… Fortios after 6.0.8 Fix from $1,6002020-03-15 HIGH 7.3 CVE-2019-2216 In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privileg… Android Mitigation only Fix from $1,9502020-03-15 CRITICAL 9.8 CVE-2020-10567EPSS 19% An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is n… Responsive Filemanager after 9.14.0 Fix from $2,3002020-03-14 MEDIUM 5.5 CVE-2020-0567 Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to enable denial of service via … Graphics Driver 26.20.100.7212+ Fix from $1,6002020-03-12 MEDIUM 6.7 CVE-2020-0526 Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. Th… Nuc Kit Nuc8i7bek Firmware Mitigation only Fix from $1,6002020-03-12 MEDIUM 5.3 CVE-2018-19516 messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equ… Kde Applications 18.12+ Fix from $1,6002020-03-12 HIGH 7.8 CVE-2020-0808 An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Eleva… Windows 10 Patch available Fix from $1,9502020-03-12 CRITICAL 9.8 CVE-2020-5203 In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GE… Fat Free Framework Patch available Fix from $2,3002020-03-11 HIGH 7.2 CVE-2020-6202 SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate th… Netweaver Application Server Java Mitigation only Fix from $1,9502020-03-10 MEDIUM 6.7 CVE-2020-0050 In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalati… Android Patch available Fix from $1,6002020-03-10 HIGH 7.8 CVE-2020-0041 KEV In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p… Android Mitigation only Fix from $1,9502020-03-10 CRITICAL 9.8 CVE-2019-7589 A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code … Entrapass 8.10+ Fix from $2,3002020-03-10 HIGH 7.5 CVE-2019-19298 A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2). … Sinvr\/sivms Video Server Patch available Fix from $1,9502020-03-10 HIGH 7.5 CVE-2019-19279 A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Spec… Siprotec 4 Mitigation only Fix from $1,9502020-03-10 CRITICAL 9.0 CVE-2020-10255 Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations against RowHammer attacks known … Ddr4 Sdram Mitigation only Fix from $2,3002020-03-10 MEDIUM 5.3 CVE-2019-12433 An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11. It has Improper Input Validation. Restricted visibility settin… GitLab after 11.11.0 Fix from $1,6002020-03-10 MEDIUM 6.1 CVE-2020-10236 An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was n… Froxlor 0.10.14+ Fix from $1,6002020-03-09