Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2019-1354EPSS 22% A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution … Visual Studio 2017 15.9.18 / 16.4.1+ Fix from $1,9502020-01-24 MEDIUM 5.5 CVE-2015-1525 audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted … Android 5.1+ Fix from $1,6002020-01-24 HIGH 7.5 CVE-2015-2689 Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which all… Tor 0.2.4.26 / 0.2.5.11+ Fix from $1,9502020-01-24 CRITICAL 9.9 CVE-2020-6965 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, … Apexpro Telemetry Server Firmware after 4.2 Fix from $2,3002020-01-24 CRITICAL 10.0 CVE-2020-6962 In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X,… Apexpro Telemetry Server Firmware after 4.2 Fix from $2,3002020-01-24 CRITICAL 10.0 CVE-2020-6963 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, … Apexpro Telemetry Server Firmware after 4.2 Fix from $2,3002020-01-24 CRITICAL 9.8 CVE-2012-5699 BabyGekko before 1.2.4 allows PHP file inclusion. Babygekko 1.2.4+ Fix from $2,3002020-01-23 CRITICAL 9.8 CVE-2019-19836 AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rc… Unleashed 9.10.2.0.84 / 9.12.3.0.136+ Fix from $2,3002020-01-22 HIGH 7.2 CVE-2011-3611 A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12. Usebb 1.0.12+ Fix from $1,9502020-01-22 HIGH 7.5 CVE-2020-6638 Grin through 2.1.1 has Insufficient Validation. Grin after 2.1.1 Fix from $1,9502020-01-21 CRITICAL 9.8 CVE-2015-2784 The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input. Papercrop 0.3.0+ Fix from $2,3002020-01-21 HIGH 7.5 CVE-2019-14010 The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd buffer map which happens to b… Mdm9607 Firmware Patch available Fix from $1,9502020-01-21 HIGH 8.3 CVE-2019-9503 The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfma… Enterprise Linux Patch available Fix from $1,9502020-01-16 MEDIUM 5.5 CVE-2019-11998 HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerabilit… Superdome Flex Server Firmware 3.20.186+ Fix from $1,6002020-01-16 HIGH 7.5 CVE-2019-13524 GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) … Rx3i Cpe100 Firmware Patch available Fix from $1,9502020-01-16 HIGH 7.1 CVE-2019-13939 A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE P… Capital Vstar 2.8.2 / 2017.02.2+ Fix from $1,9502020-01-16 MEDIUM 6.5 CVE-2019-15961 A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remo… Email Security Appliance Firmware after 0.101.4 Fix from $1,6002020-01-15 HIGH 7.5 CVE-2015-5230EPSS 9% The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of se… Debian Linux 3.4.6+ Fix from $1,9502020-01-15 HIGH 7.4 CVE-2012-1326 Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead t… Ironport Web Security Appliance after 7.5 Fix from $1,9502020-01-15 MEDIUM 6.4 CVE-2012-0334 Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle a… Ironport Web Security Appliance 7.5+ Fix from $1,6002020-01-15 HIGH 8.8 CVE-2020-7058 data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. … Cacti No fix yet Fix from $1,9502020-01-15 MEDIUM 6.0 CVE-2020-0617 A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user … Windows 10 Patch available Fix from $1,6002020-01-14 HIGH 8.8 CVE-2020-0605EPSS 17% A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successful… .net Framework Patch available Fix from $1,9502020-01-14 HIGH 8.8 CVE-2020-0606EPSS 16% A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successful… .net Framework Patch available Fix from $1,9502020-01-14 MEDIUM 5.3 CVE-2018-1002104 Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly. Nginx Ingress Controller 1.5.0+ Fix from $1,6002020-01-14 CRITICAL 9.8 CVE-2011-3203 A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2. Jcow Cms after 5.2 Fix from $2,3002020-01-14 HIGH 7.5 CVE-2020-6304 Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL6… Netweaver Internet Communication Manager \(kernel\) Mitigation only Fix from $1,9502020-01-14 HIGH 7.1 CVE-2015-3150 abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory ar… Automatic Bug Reporting Tool Patch available Fix from $1,9502020-01-14 HIGH 8.1 CVE-2014-2271 cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP… Wps Office Mitigation only Fix from $1,9502020-01-14 HIGH 7.8 CVE-2012-4603EPSS 7% Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute ar… Receiver after 12.1 Fix from $1,9502020-01-10