Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2020-0787 KEVEPSS 43% An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka… Windows 10 1507 Patch available Fix from $1,9502020-03-12 CRITICAL 9.8 CVE-2020-10181 KEVEPSS 15% goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) … Enhanced Multimedia Router Firmware Mitigation only Fix from $2,3002020-03-11 CRITICAL 9.8 CVE-2020-6207 KEVEPSS 98% SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic… Solution Manager Mitigation only Fix from $2,3002020-03-10 HIGH 7.8 CVE-2020-0069 KEV In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missin… Android 9.1.0.340 / 10.0.0.177+ Fix from $1,9502020-03-10 HIGH 7.8 CVE-2020-0041 KEV In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p… Android Mitigation only Fix from $1,9502020-03-10 HIGH 7.2 CVE-2016-11021 KEVEPSS 69% setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. Dcs 930l Firmware 2.12+ Fix from $1,9502020-03-09 HIGH 8.8 CVE-2020-10221 KEVEPSS 37% lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the… Rconfig after 3.9.4 Fix from $1,9502020-03-08 CRITICAL 9.8 CVE-2020-10189 KEVEPSS 100% Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the F… Manageengine Desktop Central 10.0.479+ Fix from $2,3002020-03-06 HIGH 7.8 CVE-2019-20500 KEVEPSS 97% D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web… Dwl 2600ap Firmware after 4.2.0.15 Fix from $1,9502020-03-05 CRITICAL 9.8 CVE-2020-9054 KEVEPSS 100% Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi… Nas326 Firmware 4.35 / 5.21+ Fix from $2,3002020-03-04 HIGH 8.8 CVE-2019-17026 KEVEPSS 47% Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in … Firefox 68.4.1 / 72.0.1+ Fix from $1,9502020-03-02 HIGH 8.8 CVE-2020-6418 KEVEPSS 79% Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 80.0.3987.122+ Fix from $1,9502020-02-27 HIGH 7.8 CVE-2020-3837 KEVEPSS 15% A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, t… Ipados 6.1.2 / 10.15.3+ Fix from $1,9502020-02-27 CRITICAL 9.8 CVE-2020-1938 KEVEPSS 99% When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as … Geode 7.0.100 / 8.5.51+ Fix from $2,3002020-02-24 MEDIUM 6.5 CVE-2020-3153 KEVEPSS 27% A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy… Anyconnect Secure Mobility Client 4.8.02042+ Fix from $1,6002020-02-19 CRITICAL 9.8 CVE-2020-7796 KEVEPSS 84% Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. Zimbra Collaboration Suite 8.8.15+ Fix from $2,3002020-02-18 HIGH 8.8 CVE-2020-0688 KEVEPSS 100% A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Micros… Exchange Server Patch available Fix from $1,9502020-02-11 HIGH 7.8 CVE-2020-0683 KEVEPSS 8% An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of… Windows 10 1507 Patch available Fix from $1,9502020-02-11 HIGH 7.5 CVE-2020-0674 KEVEPSS 87% A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi… Internet Explorer Patch available Fix from $1,9502020-02-11 HIGH 8.8 CVE-2020-0618 KEVEPSS 99% A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL… Sql Server Patch available Fix from $1,9502020-02-11 HIGH 7.5 CVE-2019-19356 KEVEPSS 28% Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fo… Wf2419 Firmware Mitigation only Fix from $1,9502020-02-07 HIGH 7.0 CVE-2019-18988 KEV TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installatio… Teamviewer after 14.7.1965 Fix from $1,9502020-02-07 HIGH 7.8 CVE-2020-8655 KEVEPSS 60% An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to… Eyesofnetwork Mitigation only Fix from $1,9502020-02-07 CRITICAL 9.8 CVE-2020-8657 KEVEPSS 92% An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ve… Eyesofnetwork Mitigation only Fix from $2,3002020-02-06 CRITICAL 9.8 CVE-2020-8644 KEVEPSS 87% PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. Playsms 1.4.3+ Fix from $2,3002020-02-05 HIGH 8.8 CVE-2020-3118 KEVEPSS 12% A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute… Ios Xr 6.6.12 / 7.0.2+ Fix from $1,9502020-02-05 CRITICAL 9.8 CVE-2020-8515 KEVEPSS 100% DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo… Vigor2960 Firmware Mitigation only Fix from $2,3002020-02-01 CRITICAL 9.8 CVE-2020-7247 KEVEPSS 99% smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… Debian Linux Patch available Fix from $2,3002020-01-29 HIGH 8.2 CVE-2019-18426 KEVEPSS 68% A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scrip… Whatsapp 0.3.9309 / 2.20.10+ Fix from $1,9502020-01-21 CRITICAL 9.8 CVE-2020-2555 KEVEPSS 97% Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are aff… Access Manager after 11.3.2 Fix from $2,3002020-01-15