Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-25506 KEVEPSS 100% D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec… Dns 320 Firmware Mitigation only Fix from $2,3002021-02-02 CRITICAL 9.8 CVE-2020-29557 KEVEPSS 54% An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achi… Dir 825 R1 Firmware after 3.0.1 Fix from $2,3002021-01-29 HIGH 7.8 CVE-2021-3156 KEVEPSS 99% Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo… Fedora 1.8.32 / 1.9.5+ Fix from $1,9502021-01-26 HIGH 7.5 CVE-2020-36193 KEVEPSS 71% Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue … Archive Tar 7.78 / 8.9.13+ Fix from $1,9502021-01-18 HIGH 8.8 CVE-2020-6572 KEVEPSS 11% Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page. Chrome 81.0.4044.92+ Fix from $1,9502021-01-14 HIGH 7.8 CVE-2021-1647 KEVEPSS 39% Microsoft Defender Remote Code Execution Vulnerability Windows Defender Patch available Fix from $1,9502021-01-12 CRITICAL 9.8 CVE-2021-3129 KEVEPSS 100% Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure u… Ignition 2.5.2+ Fix from $2,3002021-01-12 CRITICAL 9.6 CVE-2020-16017 KEV Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potent… Chrome 86.0.4240.198+ Fix from $2,3002021-01-08 HIGH 8.8 CVE-2020-16013 KEV Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a cra… Chrome 86.0.4240.198+ Fix from $1,9502021-01-08 HIGH 7.5 CVE-2020-17519 KEVEPSS 98% A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of t… Flink 1.11.3+ Fix from $1,9502021-01-05 CRITICAL 9.8 CVE-2020-10148 KEVEPSS 92% The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou… Orion Platform Mitigation only Fix from $2,3002020-12-29 MEDIUM 6.1 CVE-2020-35730 KEVEPSS 33% An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-ma… Fedora 1.2.13 / 1.3.16+ Fix from $1,6002020-12-28 CRITICAL 9.8 CVE-2020-29583 KEVEPSS 90% Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can … Usg20 Vpn Firmware Mitigation only Fix from $2,3002020-12-22 CRITICAL 9.8 CVE-2020-29574 KEV An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements… Cyberoamos after 2020-12-04 Fix from $2,3002020-12-11 CRITICAL 9.8 CVE-2020-17530 KEVEPSS 96% Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.… Struts 2.5.30+ Fix from $2,3002020-12-11 HIGH 8.4 CVE-2020-17144 KEVEPSS 37% Microsoft Exchange Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502020-12-10 MEDIUM 5.5 CVE-2020-27950 KEVEPSS 16% A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 202… Ipados 5.3.9 / 6.2.9+ Fix from $1,6002020-12-08 HIGH 7.8 CVE-2020-27932 KEVEPSS 10% A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.… Icloud 5.3.9 / 6.2.9+ Fix from $1,9502020-12-08 HIGH 7.8 CVE-2020-27930 KEVEPSS 22% A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS… Ipados 5.3.9 / 6.2.9+ Fix from $1,9502020-12-08 CRITICAL 9.1 CVE-2020-4006 KEVEPSS 17% VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. Identity Manager after 8.2 Fix from $2,3002020-11-23 HIGH 8.8 CVE-2020-13671 KEV Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and … Drupal 7.74 / 8.8.11+ Fix from $1,9502020-11-20 HIGH 7.8 CVE-2020-28949 KEVEPSS 85% Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to o… Archive Tar 1.4.12 / 7.75+ Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-17087 KEVEPSS 5% Windows Kernel Local Elevation of Privilege Vulnerability Windows 10 1507 Patch available Fix from $1,9502020-11-11 CRITICAL 9.8 CVE-2020-13927 KEVEPSS 100% The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to us… Airflow 1.10.11+ Fix from $2,3002020-11-10 CRITICAL 9.8 CVE-2020-16846 KEVEPSS 100% An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel… Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 CRITICAL 9.6 CVE-2020-16010 KEVEPSS 6% Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to p… Chrome 86.0.4240.185+ Fix from $2,3002020-11-03 HIGH 8.8 CVE-2020-16009 KEVEPSS 49% Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a cra… Chrome 86.0.241 / 86.0.622.63+ Fix from $1,9502020-11-03 CRITICAL 9.6 CVE-2020-15999 KEVEPSS 44% Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a craft… Chrome 2.10.4 / 86.0.4240.111+ Fix from $2,3002020-11-03 CRITICAL 9.8 CVE-2020-14750 KEVEPSS 99% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6… Weblogic Server Patch available Fix from $2,3002020-11-02 MEDIUM 6.1 CVE-2018-19953 KEVEPSS 24% If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the … Qts 4.2.6 / 4.3.3.1161+ Fix from $1,6002020-10-28