Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect Secure HIGH 7.2
CVE-2020-8218 KEVEPSS 32%

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution …

Fix: after 9.0
Fix from $1,950 2020-07-30
Fortios CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…

Fix: 6.0.10 / 6.2.4+
Fix from $2,300 2020-07-24
Adaptive Security Appliance Software HIGH 7.5
CVE-2020-3452 KEVEPSS 100%

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-07-22
Airflow HIGH 8.8
CVE-2020-11978 KEVEPSS 99%

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…

Fix: 1.10.11+
Fix from $1,950 2020-07-17
Weblogic Server CRITICAL 9.8
CVE-2020-14644 KEVEPSS 95%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.…

Mitigation only
Fix from $2,300 2020-07-15
Windows Server 2008 CRITICAL 10.0
CVE-2020-1350 KEVEPSS 91%

A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Serve…

Patch available
Fix from $2,300 2020-07-14
.net Core HIGH 7.8
CVE-2020-1147 KEVEPSS 94%

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source m…

Fix: after 16.6
Fix from $1,950 2020-07-14
Windows Server 2008 CRITICAL 9.0
CVE-2020-1040 KEVEPSS 7%

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user …

Patch available
Fix from $2,300 2020-07-14
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…

Mitigation only
Fix from $2,300 2020-07-14
Ac15 Firmware CRITICAL 9.8
CVE-2020-10987 KEVEPSS 80%

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the device…

Mitigation only
Fix from $2,300 2020-07-13
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8195 KEVEPSS 33%

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S…

Fix: 1.0.0.137 / 10.2.7+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Dir 610 Firmware HIGH 8.8
CVE-2020-9377 KEVEPSS 21%

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n…

Patch available
Fix from $1,950 2020-07-09
Core CRITICAL 9.8
CVE-2020-15505 KEVEPSS 100%

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0,…

Fix: 2.0.0.2 / 9.7.3+
Fix from $2,300 2020-07-07
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2020-5902 KEVEPSS 100%

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TM…

Fix: 11.6.5.2 / 12.1.5.2+
Fix from $2,300 2020-07-01
Vigor3900 Firmware CRITICAL 9.8
CVE-2020-15415 KEVEPSS 85%

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell …

Fix: 1.5.1+
Fix from $2,300 2020-06-30
Xg Firewall Firmware CRITICAL 9.8
CVE-2020-15069 KEVEPSS 11%

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.…

Fix: 17.5+
Fix from $2,300 2020-06-29
Pan Os CRITICAL 10.0
CVE-2020-2021 KEV

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (uncheck…

Fix: 8.1.15 / 9.0.9+
Fix from $2,300 2020-06-29
Tcp\/ip MEDIUM 5.4
CVE-2020-11899 KEVEPSS 19%

The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

Fix: 6.0.1.66+
Fix from $1,600 2020-06-17
Windows 10 1507 HIGH 7.8
CVE-2020-0986 KEVEPSS 16%

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of P…

Patch available
Fix from $1,950 2020-06-09
Ipados HIGH 8.8
CVE-2020-9818 KEV

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5.…

Fix: 6.2.5 / 12.4.7+
Fix from $1,950 2020-06-09
Debian Linux MEDIUM 6.1
CVE-2020-13965 KEVEPSS 77%

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am…

Fix: 1.3.12 / 1.4.5+
Fix from $1,600 2020-06-09
Ipados HIGH 7.8
CVE-2020-9859 KEV

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 S…

Fix: 6.2.6 / 10.15.5+
Fix from $1,950 2020-06-05
Spring Cloud Config HIGH 7.5
CVE-2020-5410 KEVEPSS 96%

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitra…

Fix: 2.1.9 / 2.2.3+
Fix from $1,950 2020-06-02
Pi Hole HIGH 7.2
CVE-2020-8816 KEVEPSS 78%

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

Fix: after 4.3.2
Fix from $1,950 2020-05-29
Kylin HIGH 8.8
CVE-2020-1956 KEVEPSS 97%

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …

Fix: after 2.6.5
Fix from $1,950 2020-05-22
Windows 10 1507 HIGH 7.0
CVE-2020-1054 KEVEPSS 53%

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker…

Patch available
Fix from $1,950 2020-05-21
Media Server HIGH 7.2
CVE-2020-5741 KEVEPSS 73%

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

Fix: 1.19.3+
Fix from $1,950 2020-05-08
Data Risk Manager CRITICAL 9.1
CVE-2020-4428 KEVEPSS 62%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F…

Fix: after 2.0.4
Fix from $2,300 2020-05-07
Data Risk Manager CRITICAL 9.8
CVE-2020-4427 KEVEPSS 70%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with…

Fix: after 2.0.6.1
Fix from $2,300 2020-05-07