Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2020-8218 KEVEPSS 32% A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution … Connect Secure after 9.0 Fix from $1,9502020-07-30 CRITICAL 9.8 CVE-2020-12812 KEVEPSS 49% An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe… Fortios 6.0.10 / 6.2.4+ Fix from $2,3002020-07-24 HIGH 7.5 CVE-2020-3452 KEVEPSS 100% A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c… Adaptive Security Appliance Software 6.2.3.16 / 6.3.0.6+ Fix from $1,9502020-07-22 HIGH 8.8 CVE-2020-11978 KEVEPSS 99% An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D… Airflow 1.10.11+ Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-14644 KEVEPSS 95% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.… Weblogic Server Mitigation only Fix from $2,3002020-07-15 CRITICAL 10.0 CVE-2020-1350 KEVEPSS 91% A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Serve… Windows Server 2008 Patch available Fix from $2,3002020-07-14 HIGH 7.8 CVE-2020-1147 KEVEPSS 94% A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source m… .net Core after 16.6 Fix from $1,9502020-07-14 CRITICAL 9.0 CVE-2020-1040 KEVEPSS 7% A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user … Windows Server 2008 Patch available Fix from $2,3002020-07-14 CRITICAL 10.0 CVE-2020-6287 KEVEPSS 95% SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker… Netweaver Application Server Java Mitigation only Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2020-10987 KEVEPSS 80% The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the device… Ac15 Firmware Mitigation only Fix from $2,3002020-07-13 MEDIUM 6.5 CVE-2020-8195 KEVEPSS 33% Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S… Application Delivery Controller Firmware 1.0.0.137 / 10.2.7+ Fix from $1,6002020-07-10 MEDIUM 6.5 CVE-2020-8193 KEVEPSS 88% Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW… Application Delivery Controller Firmware 10.2.7 / 10.5-70.18+ Fix from $1,6002020-07-10 HIGH 8.8 CVE-2020-9377 KEVEPSS 21% D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n… Dir 610 Firmware Patch available Fix from $1,9502020-07-09 CRITICAL 9.8 CVE-2020-15505 KEVEPSS 100% A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0,… Core 2.0.0.2 / 9.7.3+ Fix from $2,3002020-07-07 CRITICAL 9.8 CVE-2020-5902 KEVEPSS 100% In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TM… Big Ip Access Policy Manager 11.6.5.2 / 12.1.5.2+ Fix from $2,3002020-07-01 CRITICAL 9.8 CVE-2020-15415 KEVEPSS 85% On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell … Vigor3900 Firmware 1.5.1+ Fix from $2,3002020-06-30 CRITICAL 9.8 CVE-2020-15069 KEVEPSS 11% Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.… Xg Firewall Firmware 17.5+ Fix from $2,3002020-06-29 CRITICAL 10.0 CVE-2020-2021 KEV When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (uncheck… Pan Os 8.1.15 / 9.0.9+ Fix from $2,3002020-06-29 MEDIUM 5.4 CVE-2020-11899 KEVEPSS 19% The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. Tcp\/ip 6.0.1.66+ Fix from $1,6002020-06-17 HIGH 7.8 CVE-2020-0986 KEVEPSS 16% An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of P… Windows 10 1507 Patch available Fix from $1,9502020-06-09 HIGH 8.8 CVE-2020-9818 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5.… Ipados 6.2.5 / 12.4.7+ Fix from $1,9502020-06-09 MEDIUM 6.1 CVE-2020-13965 KEVEPSS 77% An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am… Debian Linux 1.3.12 / 1.4.5+ Fix from $1,6002020-06-09 HIGH 7.8 CVE-2020-9859 KEV A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 S… Ipados 6.2.6 / 10.15.5+ Fix from $1,9502020-06-05 HIGH 7.5 CVE-2020-5410 KEVEPSS 96% Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitra… Spring Cloud Config 2.1.9 / 2.2.3+ Fix from $1,9502020-06-02 HIGH 7.2 CVE-2020-8816 KEVEPSS 78% Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. Pi Hole after 4.3.2 Fix from $1,9502020-05-29 HIGH 8.8 CVE-2020-1956 KEVEPSS 97% Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is … Kylin after 2.6.5 Fix from $1,9502020-05-22 HIGH 7.0 CVE-2020-1054 KEVEPSS 53% An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker… Windows 10 1507 Patch available Fix from $1,9502020-05-21 HIGH 7.2 CVE-2020-5741 KEVEPSS 73% Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. Media Server 1.19.3+ Fix from $1,9502020-05-08 CRITICAL 9.1 CVE-2020-4428 KEVEPSS 62% IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F… Data Risk Manager after 2.0.4 Fix from $2,3002020-05-07 CRITICAL 9.8 CVE-2020-4427 KEVEPSS 70% IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… Data Risk Manager after 2.0.6.1 Fix from $2,3002020-05-07