Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dns 320 Firmware CRITICAL 9.8
CVE-2020-25506 KEVEPSS 100%

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec…

Mitigation only
Fix from $2,300 2021-02-02
Dir 825 R1 Firmware CRITICAL 9.8
CVE-2020-29557 KEVEPSS 54%

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achi…

Fix: after 3.0.1
Fix from $2,300 2021-01-29
Fedora HIGH 7.8
CVE-2021-3156 KEVEPSS 99%

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…

Fix: 1.8.32 / 1.9.5+
Fix from $1,950 2021-01-26
Archive Tar HIGH 7.5
CVE-2020-36193 KEVEPSS 71%

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue …

Fix: 7.78 / 8.9.13+
Fix from $1,950 2021-01-18
Chrome HIGH 8.8
CVE-2020-6572 KEVEPSS 11%

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Fix: 81.0.4044.92+
Fix from $1,950 2021-01-14
Windows Defender HIGH 7.8
CVE-2021-1647 KEVEPSS 39%

Microsoft Defender Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-01-12
Ignition CRITICAL 9.8
CVE-2021-3129 KEVEPSS 100%

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure u…

Fix: 2.5.2+
Fix from $2,300 2021-01-12
Chrome CRITICAL 9.6
CVE-2020-16017 KEV

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 86.0.4240.198+
Fix from $2,300 2021-01-08
Chrome HIGH 8.8
CVE-2020-16013 KEV

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 86.0.4240.198+
Fix from $1,950 2021-01-08
Flink HIGH 7.5
CVE-2020-17519 KEVEPSS 98%

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t…

Fix: 1.11.3+
Fix from $1,950 2021-01-05
Orion Platform CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…

Mitigation only
Fix from $2,300 2020-12-29
Fedora MEDIUM 6.1
CVE-2020-35730 KEVEPSS 33%

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-ma…

Fix: 1.2.13 / 1.3.16+
Fix from $1,600 2020-12-28
Usg20 Vpn Firmware CRITICAL 9.8
CVE-2020-29583 KEVEPSS 90%

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can …

Mitigation only
Fix from $2,300 2020-12-22
Cyberoamos CRITICAL 9.8
CVE-2020-29574 KEV

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements…

Fix: after 2020-12-04
Fix from $2,300 2020-12-11
Struts CRITICAL 9.8
CVE-2020-17530 KEVEPSS 96%

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.…

Fix: 2.5.30+
Fix from $2,300 2020-12-11
Exchange Server HIGH 8.4
CVE-2020-17144 KEVEPSS 37%

Microsoft Exchange Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2020-12-10
Ipados MEDIUM 5.5
CVE-2020-27950 KEVEPSS 16%

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 202…

Fix: 5.3.9 / 6.2.9+
Fix from $1,600 2020-12-08
Icloud HIGH 7.8
CVE-2020-27932 KEVEPSS 10%

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.…

Fix: 5.3.9 / 6.2.9+
Fix from $1,950 2020-12-08
Ipados HIGH 7.8
CVE-2020-27930 KEVEPSS 22%

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS…

Fix: 5.3.9 / 6.2.9+
Fix from $1,950 2020-12-08
Identity Manager CRITICAL 9.1
CVE-2020-4006 KEVEPSS 17%

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Fix: after 8.2
Fix from $2,300 2020-11-23
Drupal HIGH 8.8
CVE-2020-13671 KEV

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …

Fix: 7.74 / 8.8.11+
Fix from $1,950 2020-11-20
Archive Tar HIGH 7.8
CVE-2020-28949 KEVEPSS 85%

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o…

Fix: 1.4.12 / 7.75+
Fix from $1,950 2020-11-19
Windows 10 1507 HIGH 7.8
CVE-2020-17087 KEVEPSS 5%

Windows Kernel Local Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2020-11-11
Airflow CRITICAL 9.8
CVE-2020-13927 KEVEPSS 100%

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us…

Fix: 1.10.11+
Fix from $2,300 2020-11-10
Debian Linux CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Chrome CRITICAL 9.6
CVE-2020-16010 KEVEPSS 6%

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to p…

Fix: 86.0.4240.185+
Fix from $2,300 2020-11-03
Chrome HIGH 8.8
CVE-2020-16009 KEVEPSS 49%

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 86.0.241 / 86.0.622.63+
Fix from $1,950 2020-11-03
Chrome CRITICAL 9.6
CVE-2020-15999 KEVEPSS 44%

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 2.10.4 / 86.0.4240.111+
Fix from $2,300 2020-11-03
Weblogic Server CRITICAL 9.8
CVE-2020-14750 KEVEPSS 99%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6…

Patch available
Fix from $2,300 2020-11-02
Qts MEDIUM 6.1
CVE-2018-19953 KEVEPSS 24%

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the …

Fix: 4.2.6 / 4.3.3.1161+
Fix from $1,600 2020-10-28