Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Foreman MEDIUM 5.3
CVE-2014-0091

Foreman has improper input validation which could lead to partial Denial of Service

No fix yet
Fix from $1,600 2019-12-11
Debian Linux HIGH 7.3
CVE-2013-4245

Orca has arbitrary code execution due to insecure Python module load

Mitigation only
Fix from $1,950 2019-12-11
Windows 10 HIGH 7.8
CVE-2019-1484EPSS 9%

A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution…

Patch available
Fix from $1,950 2019-12-10
Windows 10 MEDIUM 6.0
CVE-2019-1470EPSS 6%

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…

Patch available
Fix from $1,600 2019-12-10
Windows 10 HIGH 8.2
CVE-2019-1471EPSS 8%

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2019-12-10
Chrome MEDIUM 6.5
CVE-2019-13750

Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a cra…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Firefox MEDIUM 6.5
CVE-2013-1689

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

Fix: after 19.0.2
Fix from $1,600 2019-12-10
Android HIGH 7.5
CVE-2019-2232

In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service wh…

Patch available
Fix from $1,950 2019-12-06
Qts CRITICAL 9.8
CVE-2019-7193 KEVEPSS 14%

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend…

Mitigation only
Fix from $2,300 2019-12-05
Hs Tls HIGH 7.4
CVE-2013-0243

haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections

Fix: 0.6.1+
Fix from $1,950 2019-12-05
External Provisioner MEDIUM 6.5
CVE-2019-11255

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshot…

Fix: after 1.2.1
Fix from $1,600 2019-12-05
Fedora MEDIUM 6.8
CVE-2019-19579

An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…

Fix: after 4.12.1
Fix from $1,600 2019-12-04
Olingo HIGH 7.5
CVE-2019-17555

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w…

Fix: after 4.6.0
Fix from $1,950 2019-12-04
Mod Fcgid HIGH 8.8
CVE-2016-1000104

A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.

Fix: after 2016-07-07
Fix from $1,950 2019-12-03
Openshift HIGH 8.1
CVE-2013-2103

OpenShift cartridge allows remote URL retrieval

Mitigation only
Fix from $1,950 2019-12-03
FreeBSD HIGH 7.8
CVE-2012-4576

FreeBSD: Input Validation Flaw allows local users to gain elevated privileges

No fix yet
Fix from $1,950 2019-12-02
Omnios HIGH 7.5
CVE-2019-19396

illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurre…

Mitigation only
Fix from $1,950 2019-11-29
Cd10 10 Firmware HIGH 8.1
CVE-2019-5268

Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulne…

Fix: 10.0.2.5 / 10.0.2.6+
Fix from $1,950 2019-11-29
Ruby MEDIUM 5.9
CVE-2015-1855

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properl…

Fix: 2.1.6 / 2.2.2+
Fix from $1,600 2019-11-29
Octopus Deploy MEDIUM 6.5
CVE-2019-19376

In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input valida…

Fix: 2019.6.14 / 2019.9.8+
Fix from $1,600 2019-11-28
Relion 650 Firmware HIGH 7.5
CVE-2019-18247

An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.…

Fix: after 2.1.0.1
Fix from $1,950 2019-11-27
Fortios HIGH 7.5
CVE-2019-15705

An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticate…

Fix: after 6.2.1
Fix from $1,950 2019-11-27
Debian Linux HIGH 8.1
CVE-2012-2248

An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.

Mitigation only
Fix from $1,950 2019-11-27
Cms Made Simple HIGH 7.5
CVE-2011-4310

The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.

Fix: 1.9.4.3+
Fix from $1,950 2019-11-26
Debian Linux CRITICAL 9.8
CVE-2011-4120

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured…

Fix: 2.10+
Fix from $2,300 2019-11-26
Dna Spaces\ MEDIUM 6.7
CVE-2019-15997

A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitra…

Fix: 2.0+
Fix from $1,600 2019-11-26
Unity Express MEDIUM 6.7
CVE-2019-15986

A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro…

Fix: 10.1+
Fix from $1,600 2019-11-26
Email Security Appliance Firmware MEDIUM 5.3
CVE-2019-15988

A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat…

Fix: after 12.5.0
Fix from $1,600 2019-11-26
Wireless Lan Controller Software MEDIUM 6.5
CVE-2019-15276EPSS 46%

A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause …

Fix: 8.10+
Fix from $1,600 2019-11-26
Telepresence Codec HIGH 8.8
CVE-2019-15288

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an…

Fix: 7.3.19 / 9.8.1+
Fix from $1,950 2019-11-26