Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2021-36052

XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the c…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36055

XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the con…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux MEDIUM 5.5
CVE-2021-36056

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the …

Fix: after 2020.1
Fix from $1,600 2021-09-01
Debian Linux MEDIUM 6.5
CVE-2021-40085

An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsma…

Fix: 16.4.1 / 17.2.1+
Fix from $1,600 2021-08-31
Debian Linux HIGH 8.6
CVE-2021-37712

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution …

Fix: 1.0.1.1+
Fix from $1,950 2021-08-31
Debian Linux HIGH 8.6
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v…

Fix: 1.0.1.1 / 4.4.16+
Fix from $1,950 2021-08-31
Debian Linux HIGH 8.8
CVE-2020-35633

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2…

No fix yet
Fix from $1,950 2021-08-30
Debian Linux HIGH 8.8
CVE-2020-35634

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2…

No fix yet
Fix from $1,950 2021-08-30
Debian Linux HIGH 8.8
CVE-2020-35635

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::re…

No fix yet
Fix from $1,950 2021-08-30
Debian Linux MEDIUM 6.1
CVE-2020-23226

Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) gr…

No fix yet
Fix from $1,600 2021-08-27
Debian Linux HIGH 8.6
CVE-2021-23434

This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components us…

Fix: 0.11.6+
Fix from $1,950 2021-08-27
Debian Linux HIGH 7.4
CVE-2021-3713

An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the gue…

Fix: after 6.1.0
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21840

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21841

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21842

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21848

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21849

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21850

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21834

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-21836

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-38714

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoad…

Fix: after 1.8.5
Fix from $1,950 2021-08-24
Debian Linux HIGH 8.1
CVE-2020-18771

Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information …

No fix yet
Fix from $1,950 2021-08-23
Debian Linux MEDIUM 6.3
CVE-2021-39140EPSS 6%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca…

Fix: 1.4.18+
Fix from $1,600 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39141EPSS 16%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39145

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.8
CVE-2021-39139

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux CRITICAL 9.6
CVE-2021-3693

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, thi…

Fix: after 1.8.17
Fix from $2,300 2021-08-23
Debian Linux CRITICAL 9.6
CVE-2021-3694

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this fla…

Fix: after 1.8.17
Fix from $2,300 2021-08-23
Debian Linux HIGH 7.5
CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to…

Fix: 2.2 / 2.7.18+
Fix from $1,950 2021-08-23