Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2020-4428 KEVEPSS 62% IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-F… Data Risk Manager after 2.0.4 Fix from $2,3002020-05-07 CRITICAL 9.8 CVE-2020-4427 KEVEPSS 70% IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with… Data Risk Manager after 2.0.6.1 Fix from $2,3002020-05-07 HIGH 7.5 CVE-2020-3259 KEVEPSS 69% A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c… Secure Firewall Threat Defense 6.2.3.16 / 6.3.0.6+ Fix from $1,9502020-05-06 CRITICAL 9.8 CVE-2020-12641 KEVEPSS 84% rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for … Webmail 1.2.10 / 1.3.11+ Fix from $2,3002020-05-04 CRITICAL 9.8 CVE-2020-1631 KEV A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redire… Junos Mitigation only Fix from $2,3002020-05-04 MEDIUM 6.5 CVE-2020-11652 KEVEPSS 86% An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth… Debian Linux 2019.2.4 / 3000.2+ Fix from $1,6002020-04-30 CRITICAL 9.8 CVE-2020-11651 KEVEPSS 97% An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate… Debian Linux 2019.2.4 / 3000.2+ Fix from $2,3002020-04-30 MEDIUM 6.1 CVE-2020-11023 KEVEPSS 84% In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after san… Jquery 3.5.0 / 7.70+ Fix from $1,6002020-04-29 CRITICAL 9.8 CVE-2020-12271 KEVEPSS 42% A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April… Sfos Mitigation only Fix from $2,3002020-04-27 HIGH 8.1 CVE-2020-6820 KEVEPSS 6% Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild a… Firefox 68.6.1 / 68.7.0+ Fix from $1,9502020-04-24 HIGH 8.1 CVE-2020-6819 KEV Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th… Firefox 68.6.1 / 68.7.0+ Fix from $1,9502020-04-24 CRITICAL 9.8 CVE-2020-3161 KEVEPSS 84% A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a… Ip Phone 8865 Firmware Mitigation only Fix from $2,3002020-04-15 HIGH 7.8 CVE-2020-1027 KEV An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privile… Windows 10 1507 Patch available Fix from $1,9502020-04-15 HIGH 8.8 CVE-2020-1020 KEVEPSS 65% A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted … Windows 10 1507 Patch available Fix from $1,9502020-04-15 HIGH 7.5 CVE-2020-0968 KEVEPSS 30% A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi… Internet Explorer Patch available Fix from $1,9502020-04-15 HIGH 7.8 CVE-2020-0938 KEVEPSS 69% A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted … Windows 10 1507 Patch available Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2020-2883 KEVEPSS 95% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.… Weblogic Server Mitigation only Fix from $2,3002020-04-15 HIGH 7.5 CVE-2020-11738 KEVEPSS 98% The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file param… Duplicator 1.3.28 / 3.8.7.1+ Fix from $1,9502020-04-13 CRITICAL 9.8 CVE-2020-3952 KEVEPSS 90% Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does no… Vcenter Server Mitigation only Fix from $2,3002020-04-10 HIGH 8.8 CVE-2020-5735 KEVEPSS 36% Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to cra… 1080 Lite 8ch Firmware Mitigation only Fix from $1,9502020-04-08 HIGH 8.8 CVE-2020-10199 KEVEPSS 99% Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). Nexus 3.21.2+ Fix from $1,9502020-04-01 CRITICAL 9.8 CVE-2020-5722 KEVEPSS 84% The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker c… Ucm6200 Firmware 1.0.19.20+ Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2020-7961 KEVEPSS 100% Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JS… Liferay Portal 7.2.1+ Fix from $2,3002020-03-20 CRITICAL 9.8 CVE-2020-8599 KEVEPSS 12% Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an a… Apex One Patch available Fix from $2,3002020-03-18 HIGH 8.8 CVE-2020-8468 KEVEPSS 6% Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulne… Apex One Patch available Fix from $1,9502020-03-18 HIGH 8.8 CVE-2020-8467 KEVEPSS 11% A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute ar… Apex One Patch available Fix from $1,9502020-03-18 HIGH 7.8 CVE-2020-3950 KEVEPSS 7% VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4… Fusion 5.4.0 / 11.0.1+ Fix from $1,9502020-03-17 HIGH 7.5 CVE-2020-5849 KEVEPSS 93% Unraid 6.8.0 allows authentication bypass. Unraid No fix yet Fix from $1,9502020-03-16 CRITICAL 9.8 CVE-2020-5847 KEVEPSS 96% Unraid through 6.8.0 allows Remote Code Execution. Unraid after 6.8.0 Fix from $2,3002020-03-16 CRITICAL 10.0 CVE-2020-0796 KEVEPSS 100% A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka … Windows 10 1903 Patch available Fix from $2,3002020-03-12