Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Weblogic Server CRITICAL 9.8
CVE-2020-2551 KEVEPSS 93%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affecte…

Patch available
Fix from $2,300 2020-01-15
.net Framework CRITICAL 9.8
CVE-2020-0646 KEVEPSS 99%

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Exec…

Patch available
Fix from $2,300 2020-01-14
Windows 10 1709 HIGH 7.8
CVE-2020-0638 KEV

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker wo…

Patch available
Fix from $1,950 2020-01-14
Go HIGH 8.1
CVE-2020-0601 KEVEPSS 89%

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could…

Fix: 1.12.16 / 1.13.7+
Fix from $1,950 2020-01-14
Dir 859 Firmware CRITICAL 9.8
CVE-2019-17621 KEVEPSS 90%

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute syste…

Fix: after 3.12b04
Fix from $2,300 2019-12-30
Solr HIGH 7.5
CVE-2019-17558 KEVEPSS 99%

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…

Fix: 7.7.3 / 8.4.0+
Fix from $1,950 2019-12-30
Nvms 1000 Firmware HIGH 7.5
CVE-2019-20085 KEVEPSS 96%

TVT NVMS-1000 devices allow GET /.. Directory Traversal

Mitigation only
Fix from $1,950 2019-12-30
Application Delivery Controller Firmware CRITICAL 9.8
CVE-2019-19781 KEVEPSS 100%

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Mitigation only
Fix from $2,300 2019-12-27
Mongo Express CRITICAL 9.9
CVE-2019-10758 KEVEPSS 85%

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to pe…

Fix: 0.54.0+
Fix from $2,300 2019-12-24
Sma 100 Firmware HIGH 7.5
CVE-2019-7483 KEV

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a …

Fix: 9.0.0.4+
Fix from $1,950 2019-12-19
Iphone Os HIGH 7.8
CVE-2019-8605 KEVEPSS 17%

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1…

Fix: 5.2.1 / 10.14.5+
Fix from $1,950 2019-12-18
Mac Os X HIGH 7.8
CVE-2019-8526 KEV

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain…

Fix: 10.14.4+
Fix from $1,950 2019-12-18
Safari HIGH 8.8
CVE-2019-8506 KEVEPSS 18%

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9…

Fix: 7.11 / 12.1+
Fix from $1,950 2019-12-18
Iphone Os HIGH 7.8
CVE-2019-7287 KEV

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbi…

Fix: 12.1.4+
Fix from $1,950 2019-12-18
Iphone Os HIGH 7.8
CVE-2019-7286 KEVEPSS 16%

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. …

Fix: 10.14.3 / 12.1.4+
Fix from $1,950 2019-12-18
Planning Analytics CRITICAL 9.8
CVE-2019-4716 KEVEPSS 86%

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th…

Fix: after 2.0.8
Fix from $2,300 2019-12-18
Sma 100 Firmware HIGH 7.5
CVE-2019-7481 KEVEPSS 100%

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 ve…

Fix: 9.0.0.4+
Fix from $1,950 2019-12-17
Ui For Asp.net Ajax CRITICAL 9.8
CVE-2019-18935 KEVEPSS 100%

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploi…

Fix: after 2020.1.114
Fix from $2,300 2019-12-11
Windows 10 1507 HIGH 7.8
CVE-2019-1458 KEVEPSS 74%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…

Patch available
Fix from $1,950 2019-12-10
Horizon Daas CRITICAL 9.8
CVE-2019-5544 KEVEPSS 97%

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Crit…

Fix: 9.0.0.0+
Fix from $2,300 2019-12-06
Photo Station CRITICAL 9.8
CVE-2019-7195 KEVEPSS 90%

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP rec…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Photo Station CRITICAL 9.8
CVE-2019-7194 KEVEPSS 83%

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP rec…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Qts CRITICAL 9.8
CVE-2019-7193 KEVEPSS 14%

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend…

Mitigation only
Fix from $2,300 2019-12-05
Photo Station CRITICAL 9.8
CVE-2019-7192 KEVEPSS 88%

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP reco…

Fix: 5.2.11 / 5.4.9+
Fix from $2,300 2019-12-05
Rv016 Multi Wan Vpn Firmware HIGH 8.8
CVE-2019-15271 KEVEPSS 6%

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker…

Fix: 4.2.3.10+
Fix from $1,950 2019-11-26
Chrome MEDIUM 6.5
CVE-2019-5825 KEVEPSS 56%

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 73.0.3683.86+
Fix from $1,600 2019-11-25
Chrome HIGH 8.8
CVE-2019-13720 KEVEPSS 49%

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 78.0.3904.87+
Fix from $1,950 2019-11-25
Freepbx CRITICAL 9.8
CVE-2019-19006 KEVEPSS 37%

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

Fix: after 15.0.16.26
Fix from $2,300 2019-11-21
Fortios MEDIUM 6.5
CVE-2019-6693 KEVEPSS 6%

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup f…

Fix: after 6.0.6
Fix from $1,600 2019-11-21
Internet Explorer HIGH 7.5
CVE-2019-1429 KEVEPSS 73%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi…

Patch available
Fix from $1,950 2019-11-12