Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qts CRITICAL 9.8
CVE-2018-19949 KEVEPSS 24%

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the fo…

Fix: 4.2.6 / 4.3.3.1161+
Fix from $2,300 2020-10-28
Qts MEDIUM 5.4
CVE-2018-19943 KEVEPSS 18%

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in t…

Fix: 4.2.6 / 4.3.3.1252+
Fix from $1,600 2020-10-28
Connect Secure HIGH 7.2
CVE-2020-8260 KEVEPSS 96%

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution …

Fix: after 9.0
Fix from $1,950 2020-10-28
Secure Firewall Threat Defense MEDIUM 6.1
CVE-2020-3580 KEVEPSS 86%

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) S…

Fix: 6.4.0.12 / 6.6.4+
Fix from $1,600 2020-10-21
Weblogic Server HIGH 7.2
CVE-2020-14883 KEVEPSS 98%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6…

Mitigation only
Fix from $1,950 2020-10-21
Weblogic Server CRITICAL 9.8
CVE-2020-14882 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6…

Mitigation only
Fix from $2,300 2020-10-21
Solaris CRITICAL 10.0
CVE-2020-14871 KEVEPSS 80%

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are …

Fix: 11.1+
Fix from $2,300 2020-10-21
Business Intelligence HIGH 7.5
CVE-2020-14864 KEVEPSS 97%

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported version…

Mitigation only
Fix from $1,950 2020-10-21
Cloud Foundation CRITICAL 9.8
CVE-2020-3992 KEVEPSS 83%

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after…

Fix: 3.10.1.2 / 4.1.0.1+
Fix from $2,300 2020-10-20
Ipados MEDIUM 5.5
CVE-2020-9934 KEV

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPa…

Fix: 10.15.6 / 13.6+
Fix from $1,600 2020-10-16
Ipados HIGH 7.8
CVE-2020-9907 KEV

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application…

Fix: 13.4.8 / 13.6+
Fix from $1,950 2020-10-16
Sonicos CRITICAL 9.8
CVE-2020-5135 KEVEPSS 25%

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sendin…

Fix: after 6.5.4.7
Fix from $2,300 2020-10-12
Jgs516pe Firmware CRITICAL 9.8
CVE-2020-26919 KEVEPSS 57%

NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

Fix: 2.6.0.43+
Fix from $2,300 2020-10-09
Connect Secure HIGH 7.2
CVE-2020-8243 KEVEPSS 91%

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform …

Fix: after 9.0
Fix from $1,950 2020-09-30
Unified Threat Management CRITICAL 9.8
CVE-2020-25223 KEVEPSS 97%

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Fix: 9.511 / 9.607+
Fix from $2,300 2020-09-25
Ios Xr HIGH 8.6
CVE-2020-3569 KEV

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, r…

Fix: 6.5.2+
Fix from $1,950 2020-09-23
File Manager CRITICAL 9.8
CVE-2020-25213 KEVEPSS 97%

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it rename…

Fix: 6.9+
Fix from $2,300 2020-09-09
Dcs 4703e Firmware HIGH 8.8
CVE-2020-25079 KEVEPSS 53%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comma…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
Dcs 4603 Firmware HIGH 7.5
CVE-2020-25078 KEVEPSS 98%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint al…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
Apex One HIGH 7.8
CVE-2020-24557 KEV

A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particul…

Mitigation only
Fix from $1,950 2020-09-01
Tl Wa855re Firmware HIGH 8.8
CVE-2020-24363 KEVEPSS 21%

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a fac…

Fix: 200731+
Fix from $1,950 2020-08-31
Ios Xr HIGH 8.6
CVE-2020-3566 KEV

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote att…

Mitigation only
Fix from $1,950 2020-08-29
Acrobat Dc HIGH 7.8
CVE-2020-9715 KEVEPSS 48%

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-…

Fix: after 20.009.20074
Fix from $1,950 2020-08-19
Fedora MEDIUM 5.5
CVE-2020-1472 KEVEPSS 100%

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, u…

Patch available
Fix from $1,600 2020-08-17
Windows 10 1507 HIGH 7.8
CVE-2020-1464 KEVEPSS 41%

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could b…

Patch available
Fix from $1,950 2020-08-17
Internet Explorer HIGH 7.8
CVE-2020-1380 KEVEPSS 24%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability c…

Patch available
Fix from $1,950 2020-08-17
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2020-3433 KEVEPSS 10%

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, …

Fix: 4.9.00086+
Fix from $1,950 2020-08-17
Fortios MEDIUM 6.5
CVE-2019-5591 KEVEPSS 18%

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper…

Fix: after 6.2.0
Fix from $1,600 2020-08-14
Fuel Cms CRITICAL 9.8
CVE-2020-17463 KEVEPSS 90%

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

Mitigation only
Fix from $2,300 2020-08-13
Vbulletin CRITICAL 9.8
CVE-2020-17496 KEVEPSS 88%

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.…

Fix: after 5.6.2
Fix from $2,300 2020-08-12