Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Prime Infrastructure CRITICAL 9.8
CVE-2019-15958

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticat…

Fix: 3.0.2 / 3.4.2+
Fix from $2,300 2019-11-26
Querytree CRITICAL 9.8
CVE-2019-19249

Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.

Patch available
Fix from $2,300 2019-11-25
Chrome HIGH 8.8
CVE-2019-5856

Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process …

Fix: 76.0.3809.87+
Fix from $1,950 2019-11-25
Chrome HIGH 8.8
CVE-2019-5858

Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code…

Fix: 76.0.3809.87+
Fix from $1,950 2019-11-25
Chrome MEDIUM 6.5
CVE-2019-5862

Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to…

Fix: 76.0.3809.87+
Fix from $1,600 2019-11-25
Chrome MEDIUM 6.5
CVE-2019-5852

Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive informati…

Fix: 76.0.3809.87+
Fix from $1,600 2019-11-25
Chrome MEDIUM 5.5
CVE-2019-13707

Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a …

Fix: 78.0.3904.70+
Fix from $1,600 2019-11-25
Chrome HIGH 8.8
CVE-2019-13692

Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafte…

Fix: 77.0.3865.75+
Fix from $1,950 2019-11-25
Opendnssec CRITICAL 9.8
CVE-2012-5582

opendnssec misuses libcurl API

No fix yet
Fix from $2,300 2019-11-25
Debian Linux HIGH 7.5
CVE-2014-1936

rc before 1.7.1-5 insecurely creates temporary files.

Fix: 1.7.1-5+
Fix from $1,950 2019-11-21
Gamera HIGH 7.5
CVE-2014-1937

Gamera before 3.4.1 insecurely creates temporary files.

Fix: 3.4.1+
Fix from $1,950 2019-11-21
Apq8053 Firmware MEDIUM 5.5
CVE-2019-10535

Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdra…

Patch available
Fix from $1,600 2019-11-21
Apq8053 Firmware HIGH 7.8
CVE-2019-10563

Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firmware in Snapdragon Auto, Snap…

Patch available
Fix from $1,950 2019-11-21
Enterprise Mrg CRITICAL 9.8
CVE-2012-3460

cumin: At installation postgresql database user created without password

Mitigation only
Fix from $2,300 2019-11-21
Fedora HIGH 7.5
CVE-2012-4524

xlockmore before 5.43 'dclock' security bypass vulnerability

Fix: 5.43+
Fix from $1,950 2019-11-21
Openshift Origin MEDIUM 5.5
CVE-2014-0084

Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.…

Fix: 2014-02-14+
Fix from $1,600 2019-11-21
Debian Linux MEDIUM 5.3
CVE-2014-1935

9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.

No fix yet
Fix from $1,600 2019-11-21
Debian Linux HIGH 7.5
CVE-2012-2350

pam_shield before 0.9.4: Default configuration does not perform protective action

Fix: 0.9.4+
Fix from $1,950 2019-11-21
Ubuntu Linux HIGH 7.5
CVE-2012-3543

mono 2.10.x ASP.NET Web Form Hash collision DoS

Fix: after 2.10.12
Fix from $1,950 2019-11-21
Slackware Linux CRITICAL 9.8
CVE-2013-7171EPSS 6%

Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow rem…

Mitigation only
Fix from $2,300 2019-11-21
Slackware Linux HIGH 7.8
CVE-2013-7172

Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which c…

Mitigation only
Fix from $1,950 2019-11-21
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2013-2093EPSS 5%

Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary …

Patch available
Fix from $2,300 2019-11-20
Debian Linux HIGH 7.5
CVE-2013-1816

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially craf…

Fix: 1.19.4 / 1.20.3+
Fix from $1,950 2019-11-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-1607

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows re…

Fix: 1.4.19 / 2.0.27+
Fix from $1,600 2019-11-20
Statusnet CRITICAL 9.8
CVE-2010-4660

Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..

Fix: after 2010
Fix from $2,300 2019-11-20
Debian Linux HIGH 7.5
CVE-2011-0529

Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.

Fix: 0.12.5+
Fix from $1,950 2019-11-20
Debian Linux CRITICAL 9.8
CVE-2011-1028

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_s…

Fix: 3.0.7+
Fix from $2,300 2019-11-20
Cf Deployment HIGH 8.6
CVE-2019-11289

Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HT…

Fix: 0.193.0 / 12.8.0+
Fix from $1,950 2019-11-19
Ktsuss HIGH 7.8
CVE-2011-2922

ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GT…

Fix: after 1.4
Fix from $1,950 2019-11-19
Falconpl HIGH 7.5
CVE-2012-6070

Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.

Fix: 0.9.6.9+
Fix from $1,950 2019-11-19