Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Secure Firewall Threat Defense HIGH 7.5
CVE-2020-3259 KEVEPSS 69%

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c…

Fix: 6.2.3.16 / 6.3.0.6+
Fix from $1,950 2020-05-06
Webmail CRITICAL 9.8
CVE-2020-12641 KEVEPSS 84%

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for …

Fix: 1.2.10 / 1.3.11+
Fix from $2,300 2020-05-04
Junos CRITICAL 9.8
CVE-2020-1631 KEV

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redire…

Mitigation only
Fix from $2,300 2020-05-04
Debian Linux MEDIUM 6.5
CVE-2020-11652 KEVEPSS 86%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth…

Fix: 2019.2.4 / 3000.2+
Fix from $1,600 2020-04-30
Debian Linux CRITICAL 9.8
CVE-2020-11651 KEVEPSS 97%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate…

Fix: 2019.2.4 / 3000.2+
Fix from $2,300 2020-04-30
Jquery MEDIUM 6.1
CVE-2020-11023 KEVEPSS 84%

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after san…

Fix: 3.5.0 / 7.70+
Fix from $1,600 2020-04-29
Sfos CRITICAL 9.8
CVE-2020-12271 KEVEPSS 42%

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April…

Mitigation only
Fix from $2,300 2020-04-27
Firefox HIGH 8.1
CVE-2020-6820 KEVEPSS 6%

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild a…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 8.1
CVE-2020-6819 KEV

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Ip Phone 8865 Firmware CRITICAL 9.8
CVE-2020-3161 KEVEPSS 84%

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a…

Mitigation only
Fix from $2,300 2020-04-15
Windows 10 1507 HIGH 7.8
CVE-2020-1027 KEV

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privile…

Patch available
Fix from $1,950 2020-04-15
Windows 10 1507 HIGH 8.8
CVE-2020-1020 KEVEPSS 65%

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted …

Patch available
Fix from $1,950 2020-04-15
Internet Explorer HIGH 7.5
CVE-2020-0968 KEVEPSS 30%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi…

Patch available
Fix from $1,950 2020-04-15
Windows 10 1507 HIGH 7.8
CVE-2020-0938 KEVEPSS 69%

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted …

Patch available
Fix from $1,950 2020-04-15
Weblogic Server CRITICAL 9.8
CVE-2020-2883 KEVEPSS 95%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.…

Mitigation only
Fix from $2,300 2020-04-15
Duplicator HIGH 7.5
CVE-2020-11738 KEVEPSS 98%

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file param…

Fix: 1.3.28 / 3.8.7.1+
Fix from $1,950 2020-04-13
Vcenter Server CRITICAL 9.8
CVE-2020-3952 KEVEPSS 90%

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no…

Mitigation only
Fix from $2,300 2020-04-10
1080 Lite 8ch Firmware HIGH 8.8
CVE-2020-5735 KEVEPSS 36%

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to cra…

Mitigation only
Fix from $1,950 2020-04-08
Nexus HIGH 8.8
CVE-2020-10199 KEVEPSS 99%

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Fix: 3.21.2+
Fix from $1,950 2020-04-01
Ucm6200 Firmware CRITICAL 9.8
CVE-2020-5722 KEVEPSS 84%

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker c…

Fix: 1.0.19.20+
Fix from $2,300 2020-03-23
Liferay Portal CRITICAL 9.8
CVE-2020-7961 KEVEPSS 100%

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JS…

Fix: 7.2.1+
Fix from $2,300 2020-03-20
Apex One CRITICAL 9.8
CVE-2020-8599 KEVEPSS 12%

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an a…

Patch available
Fix from $2,300 2020-03-18
Apex One HIGH 8.8
CVE-2020-8468 KEVEPSS 6%

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulne…

Patch available
Fix from $1,950 2020-03-18
Apex One HIGH 8.8
CVE-2020-8467 KEVEPSS 11%

A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute ar…

Patch available
Fix from $1,950 2020-03-18
Fusion HIGH 7.8
CVE-2020-3950 KEVEPSS 7%

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4…

Fix: 5.4.0 / 11.0.1+
Fix from $1,950 2020-03-17
Unraid HIGH 7.5
CVE-2020-5849 KEVEPSS 93%

Unraid 6.8.0 allows authentication bypass.

No fix yet
Fix from $1,950 2020-03-16
Unraid CRITICAL 9.8
CVE-2020-5847 KEVEPSS 96%

Unraid through 6.8.0 allows Remote Code Execution.

Fix: after 6.8.0
Fix from $2,300 2020-03-16
Windows 10 1903 CRITICAL 10.0
CVE-2020-0796 KEVEPSS 100%

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka …

Patch available
Fix from $2,300 2020-03-12
Windows 10 1507 HIGH 7.8
CVE-2020-0787 KEVEPSS 43%

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka…

Patch available
Fix from $1,950 2020-03-12
Enhanced Multimedia Router Firmware CRITICAL 9.8
CVE-2020-10181 KEVEPSS 15%

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) …

Mitigation only
Fix from $2,300 2020-03-11