Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Passenger HIGH 7.5
CVE-2012-6135

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

Patch available
Fix from $1,950 2019-11-19
Enterprise Linux HIGH 7.5
CVE-2011-4967

tog-Pegasus has a package hash collision DoS vulnerability

Fix: 2.12+
Fix from $1,950 2019-11-19
Enterprise Linux MEDIUM 5.5
CVE-2014-5118

Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability

Fix: 1.8.2+
Fix from $1,600 2019-11-18
Jenkins HIGH 8.8
CVE-2012-4438

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execut…

Fix: 1.466.2 / 1.482+
Fix from $1,950 2019-11-18
Slp Validate MEDIUM 6.1
CVE-2019-16761

A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.…

Patch available
Fix from $1,600 2019-11-15
Slpjs MEDIUM 6.1
CVE-2019-16762

A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm packa…

Fix: 0.21.4+
Fix from $1,600 2019-11-15
Big Ip Access Policy Manager MEDIUM 5.5
CVE-2019-6663

The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow…

Fix: after 15.0.1
Fix from $1,600 2019-11-15
Debian Linux CRITICAL 9.8
CVE-2011-0703

In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 ses…

Fix: 0.0.3+
Fix from $2,300 2019-11-15
Debian Linux MEDIUM 6.5
CVE-2018-12207

Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to …

Fix: after 15.0.1
Fix from $1,600 2019-11-14
Graphics Driver MEDIUM 5.5
CVE-2019-11089

Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to pot…

Fix: 25.20.100.6519+
Fix from $1,600 2019-11-14
Graphics Driver MEDIUM 5.5
CVE-2019-14591

Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enabl…

Fix: 26.20.100.7209+
Fix from $1,600 2019-11-14
Ethernet Controller X710 Tm4 Firmware MEDIUM 5.5
CVE-2019-0147

Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to pote…

Fix: 7.0 / 24.0+
Fix from $1,600 2019-11-14
Ethernet Controller X710 Tm4 Firmware MEDIUM 5.5
CVE-2019-0149

Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to p…

Fix: 2.8.43 / 24.0+
Fix from $1,600 2019-11-14
Baseboard Management Controller Firmware HIGH 7.5
CVE-2019-11175

Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of …

Fix: 2.18+
Fix from $1,950 2019-11-14
Baseboard Management Controller Firmware MEDIUM 6.5
CVE-2019-11179

Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information …

Fix: 2.18+
Fix from $1,600 2019-11-14
Baseboard Management Controller Firmware HIGH 7.5
CVE-2019-11180

Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of …

Fix: 2.18+
Fix from $1,950 2019-11-14
Software Guard Extensions Sdk HIGH 7.8
CVE-2019-14566

Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosur…

Mitigation only
Fix from $1,950 2019-11-14
Xeon Platinum 8253 Firmware HIGH 8.2
CVE-2019-11137

Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Pro…

Mitigation only
Fix from $1,950 2019-11-14
Moodle HIGH 8.2
CVE-2012-1168

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

Fix: 2.2.2+
Fix from $1,950 2019-11-14
Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2019-0396

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently valida…

Mitigation only
Fix from $1,950 2019-11-13
Android MEDIUM 6.7
CVE-2019-9467

In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privileg…

Mitigation only
Fix from $1,600 2019-11-13
Android HIGH 7.8
CVE-2019-2192

In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2019-11-13
Android HIGH 7.8
CVE-2019-2195

In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to loc…

Mitigation only
Fix from $1,950 2019-11-13
Web Chat MEDIUM 6.5
CVE-2019-16949

An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address sp…

No fix yet
Fix from $1,600 2019-11-13
P20 Pro Firmware MEDIUM 5.5
CVE-2019-5230

P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C0…

Mitigation only
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.5
CVE-2010-3439

It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download co…

No fix yet
Fix from $1,600 2019-11-12
Windows 10 HIGH 8.4
CVE-2019-1397

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2019-11-12
Windows 10 HIGH 8.4
CVE-2019-1398

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2019-11-12
Windows 10 MEDIUM 6.2
CVE-2019-1399

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest o…

Patch available
Fix from $1,600 2019-11-12
Windows 10 HIGH 8.4
CVE-2019-1389

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2019-11-12