Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.1 CVE-2019-14082 Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Snapdragon Consumer Electronics… Ipq8074 Firmware Mitigation only Fix from $2,3002020-03-05 CRITICAL 9.1 CVE-2019-10552 Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cmd in Snapdragon Aut… Apq8009 Firmware No fix yet Fix from $2,3002020-03-05 CRITICAL 9.1 CVE-2019-10577 Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to denial of service in Snapdrago… Apq8009 Firmware Mitigation only Fix from $2,3002020-03-05 HIGH 7.5 CVE-2020-10101 An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message… Zammad after 3.2.0 Fix from $1,9502020-03-05 HIGH 7.8 CVE-2020-3127 Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an at… Webex Meetings 1.3.43 / 3.0+ Fix from $1,9502020-03-04 HIGH 7.8 CVE-2020-3128 Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an at… Webex Meetings 1.3.49 / 3.0+ Fix from $1,9502020-03-04 MEDIUM 5.3 CVE-2020-3164 A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), … Cloud Email Security 13.6.0+ Fix from $1,6002020-03-04 HIGH 7.5 CVE-2020-5403 Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of… Reactor Netty Mitigation only Fix from $1,9502020-03-03 CRITICAL 9.8 CVE-2020-8132 Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based … Pdf Image after 2.0.0 Fix from $2,3002020-02-28 HIGH 7.5 CVE-2020-9430 In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg… Wireshark after 3.2.1 Fix from $1,9502020-02-27 HIGH 8.8 CVE-2020-3846 A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3… Icloud 6.1.2 / 7.17+ Fix from $1,9502020-02-27 HIGH 7.8 CVE-2020-3856 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, … Ipados 6.1.2 / 10.15.3+ Fix from $1,9502020-02-27 HIGH 7.8 CVE-2020-3860 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, watchOS 6.1.2. An applic… Ipados 6.1.2 / 13.3.1+ Fix from $1,9502020-02-27 MEDIUM 5.5 CVE-2020-3839 A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read … Mac Os X 10.15.3+ Fix from $1,6002020-02-27 MEDIUM 5.3 CVE-2020-3170 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to un… Nx Os 8.2 / 8.4+ Fix from $1,6002020-02-26 HIGH 8.8 CVE-2020-3172 A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent atta… Firepower Extensible Operating System 2.6.1.187 / 2.7.1.106+ Fix from $1,9502020-02-26 MEDIUM 6.7 CVE-2020-3166 A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying ope… Secure Firewall Threat Defense 2.2.2.97 / 2.3.1.155+ Fix from $1,6002020-02-26 MEDIUM 6.5 CVE-2019-19992 An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to read XML files on the fi… Visual Access Manager after 4.29.0 Fix from $1,6002020-02-26 CRITICAL 9.8 CVE-2020-4212EPSS 15% IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP … Spectrum Protect 10.1.5+ Fix from $2,3002020-02-24 HIGH 7.5 CVE-2020-5243 uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular … Uap Core 0.7.3+ Fix from $1,9502020-02-21 MEDIUM 6.8 CVE-2020-6977 A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow … Vivid E95 Firmware Mitigation only Fix from $1,6002020-02-20 HIGH 7.5 CVE-2015-4410EPSS 6% The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a den… Moped Patch available Fix from $1,9502020-02-20 CRITICAL 9.8 CVE-2014-4657 The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.5.4+ Fix from $2,3002020-02-20 MEDIUM 6.5 CVE-2015-2923 The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to reconfigure a hop-limit sett… FreeBSD 10.1+ Fix from $1,6002020-02-20 MEDIUM 5.3 CVE-2020-3160 A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, rem… Meeting Server 2.8.0+ Fix from $1,6002020-02-19 CRITICAL 9.8 CVE-2014-4651 It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to acc… Jclouds 1.8.0+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2015-1425 JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities Gecko Cms No fix yet Fix from $2,3002020-02-18 HIGH 8.8 CVE-2020-1811 GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions… Gaussdb 200 Mitigation only Fix from $1,9502020-02-18 HIGH 7.5 CVE-2020-1828 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC… Nip6800 Firmware Mitigation only Fix from $1,9502020-02-17 CRITICAL 9.8 CVE-2013-3738 A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali… Zabbix Patch available Fix from $2,3002020-02-17