Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chamilo Lms HIGH 7.5
CVE-2012-4030

Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary…

Fix: 1.8.8.6+
Fix from $1,950 2020-01-10
Status2k HIGH 8.8
CVE-2014-5092EPSS 7%

Status2k allows Remote Command Execution in admin/options/editpl.php.

No fix yet
Fix from $1,950 2020-01-10
Norton Mobile Security MEDIUM 5.3
CVE-2016-6585

A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduc…

Fix: 3.16+
Fix from $1,600 2020-01-08
Tc7230 Steb Firmware CRITICAL 9.8
CVE-2019-19495

The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem vi…

No fix yet
Fix from $2,300 2020-01-08
It Management Suite MEDIUM 6.5
CVE-2016-6589

A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.

No fix yet
Fix from $1,600 2020-01-08
Enterprise Linux HIGH 7.3
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro…

Fix: 2.13+
Fix from $1,950 2020-01-07
Openlitespeed CRITICAL 9.8
CVE-2020-5519

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App…

Fix: 1.6.5+
Fix from $2,300 2020-01-06
Mrsid HIGH 7.8
CVE-2013-3945

The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.

Fix: 4.37+
Fix from $1,950 2020-01-02
Docker CRITICAL 9.8
CVE-2014-0048EPSS 7%

An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

Fix: 1.5.0+
Fix from $2,300 2020-01-02
Rovinbhandari Ftp HIGH 7.5
CVE-2019-9668

An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to cause a denial …

Fix: after 2012-03-28
Fix from $1,950 2019-12-31
Senkas Kolibri CRITICAL 9.8
CVE-2014-5289EPSS 12%

Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.

No fix yet
Fix from $2,300 2019-12-27
WordPress CRITICAL 9.8
CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sa…

Fix: 5.3.1+
Fix from $2,300 2019-12-27
M5 Lite 10 Firmware CRITICAL 9.8
CVE-2019-19398

M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an at…

Mitigation only
Fix from $2,300 2019-12-26
P30 Firmware HIGH 7.5
CVE-2019-5266

Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnera…

Mitigation only
Fix from $1,950 2019-12-23
Ceph Storage MEDIUM 6.5
CVE-2019-19337

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse …

Mitigation only
Fix from $1,600 2019-12-23
Hg100 Firmware HIGH 7.5
CVE-2019-15910

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover Zi…

No fix yet
Fix from $1,950 2019-12-20
Hg100 Firmware HIGH 7.5
CVE-2019-15912

An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust cen…

No fix yet
Fix from $1,950 2019-12-20
Dgnwg03lm Firmware HIGH 7.5
CVE-2019-15914

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin pro…

No fix yet
Fix from $1,950 2019-12-20
Dgnwg03lm Firmware HIGH 7.5
CVE-2019-15915

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to…

No fix yet
Fix from $1,950 2019-12-20
Debian Linux HIGH 7.5
CVE-2012-6111

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

Mitigation only
Fix from $1,950 2019-12-20
Debian Linux HIGH 7.8
CVE-2012-3409

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

Fix: 99+
Fix from $1,950 2019-12-20
Backdrop Cms HIGH 7.2
CVE-2019-19902

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives thr…

Fix: 1.13.5 / 1.14.2+
Fix from $1,950 2019-12-19
Converged Security Management Engine Firmware MEDIUM 6.7
CVE-2019-11108

Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable es…

Fix: 12.0.45 / 13.0.10+
Fix from $1,600 2019-12-18
Active Management Technology Firmware MEDIUM 6.8
CVE-2019-11086

Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation…

Fix: 12.0.45+
Fix from $1,600 2019-12-18
Converged Security Management Engine Firmware MEDIUM 6.7
CVE-2019-11087

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) …

Fix: 3.1.70 / 4.0.20+
Fix from $1,600 2019-12-18
Active Management Technology Firmware HIGH 8.8
CVE-2019-11088

Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user …

Fix: 11.8.70 / 11.11.70+
Fix from $1,950 2019-12-18
Converged Security Management Engine Firmware HIGH 7.8
CVE-2019-11103

Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated us…

Fix: 12.0.45 / 13.0.10+
Fix from $1,950 2019-12-18
Converged Security Management Engine Firmware HIGH 7.8
CVE-2019-11104

Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R…

Fix: 3.1.70 / 4.0.20+
Fix from $1,950 2019-12-18
Active Management Technology Firmware CRITICAL 9.8
CVE-2019-11107

Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escala…

Fix: 12.0.45+
Fix from $2,300 2019-12-18
Active Management Technology Firmware HIGH 8.1
CVE-2019-0131

Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user …

Fix: 11.8.70 / 11.11.70+
Fix from $1,950 2019-12-18