Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1507 HIGH 7.8
CVE-2020-0787 KEVEPSS 43%

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka…

Patch available
Fix from $1,950 2020-03-12
Enhanced Multimedia Router Firmware CRITICAL 9.8
CVE-2020-10181 KEVEPSS 15%

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) …

Mitigation only
Fix from $2,300 2020-03-11
Solution Manager CRITICAL 9.8
CVE-2020-6207 KEVEPSS 98%

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic…

Mitigation only
Fix from $2,300 2020-03-10
Android HIGH 7.8
CVE-2020-0069 KEV

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missin…

Fix: 9.1.0.340 / 10.0.0.177+
Fix from $1,950 2020-03-10
Android HIGH 7.8
CVE-2020-0041 KEV

In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2020-03-10
Dcs 930l Firmware HIGH 7.2
CVE-2016-11021 KEVEPSS 69%

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

Fix: 2.12+
Fix from $1,950 2020-03-09
Rconfig HIGH 8.8
CVE-2020-10221 KEVEPSS 37%

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the…

Fix: after 3.9.4
Fix from $1,950 2020-03-08
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-10189 KEVEPSS 100%

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the F…

Fix: 10.0.479+
Fix from $2,300 2020-03-06
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20500 KEVEPSS 97%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web…

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Nas326 Firmware CRITICAL 9.8
CVE-2020-9054 KEVEPSS 100%

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi…

Fix: 4.35 / 5.21+
Fix from $2,300 2020-03-04
Firefox HIGH 8.8
CVE-2019-17026 KEVEPSS 47%

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in …

Fix: 68.4.1 / 72.0.1+
Fix from $1,950 2020-03-02
Chrome HIGH 8.8
CVE-2020-6418 KEVEPSS 79%

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 80.0.3987.122+
Fix from $1,950 2020-02-27
Ipados HIGH 7.8
CVE-2020-3837 KEVEPSS 15%

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, t…

Fix: 6.1.2 / 10.15.3+
Fix from $1,950 2020-02-27
Geode CRITICAL 9.8
CVE-2020-1938 KEVEPSS 99%

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as …

Fix: 7.0.100 / 8.5.51+
Fix from $2,300 2020-02-24
Anyconnect Secure Mobility Client MEDIUM 6.5
CVE-2020-3153 KEVEPSS 27%

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy…

Fix: 4.8.02042+
Fix from $1,600 2020-02-19
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2020-7796 KEVEPSS 84%

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Fix: 8.8.15+
Fix from $2,300 2020-02-18
Exchange Server HIGH 8.8
CVE-2020-0688 KEVEPSS 100%

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Micros…

Patch available
Fix from $1,950 2020-02-11
Windows 10 1507 HIGH 7.8
CVE-2020-0683 KEVEPSS 8%

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of…

Patch available
Fix from $1,950 2020-02-11
Internet Explorer HIGH 7.5
CVE-2020-0674 KEVEPSS 87%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi…

Patch available
Fix from $1,950 2020-02-11
Sql Server HIGH 8.8
CVE-2020-0618 KEVEPSS 99%

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL…

Patch available
Fix from $1,950 2020-02-11
Wf2419 Firmware HIGH 7.5
CVE-2019-19356 KEVEPSS 28%

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fo…

Mitigation only
Fix from $1,950 2020-02-07
Teamviewer HIGH 7.0
CVE-2019-18988 KEV

TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installatio…

Fix: after 14.7.1965
Fix from $1,950 2020-02-07
Eyesofnetwork HIGH 7.8
CVE-2020-8655 KEVEPSS 60%

An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to…

Mitigation only
Fix from $1,950 2020-02-07
Eyesofnetwork CRITICAL 9.8
CVE-2020-8657 KEVEPSS 92%

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ve…

Mitigation only
Fix from $2,300 2020-02-06
Playsms CRITICAL 9.8
CVE-2020-8644 KEVEPSS 87%

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

Fix: 1.4.3+
Fix from $2,300 2020-02-05
Ios Xr HIGH 8.8
CVE-2020-3118 KEVEPSS 12%

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute…

Fix: 6.6.12 / 7.0.2+
Fix from $1,950 2020-02-05
Vigor2960 Firmware CRITICAL 9.8
CVE-2020-8515 KEVEPSS 100%

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo…

Mitigation only
Fix from $2,300 2020-02-01
Debian Linux CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…

Patch available
Fix from $2,300 2020-01-29
Whatsapp HIGH 8.2
CVE-2019-18426 KEVEPSS 68%

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scrip…

Fix: 0.3.9309 / 2.20.10+
Fix from $1,950 2020-01-21
Access Manager CRITICAL 9.8
CVE-2020-2555 KEVEPSS 97%

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are aff…

Fix: after 11.3.2
Fix from $2,300 2020-01-15