Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 MEDIUM 6.8
CVE-2019-0712EPSS 5%

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,600 2019-11-12
Windows 10 CRITICAL 9.1
CVE-2019-0719EPSS 11%

A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authentica…

Patch available
Fix from $2,300 2019-11-12
Windows 10 CRITICAL 9.1
CVE-2019-0721EPSS 10%

A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authentica…

Patch available
Fix from $2,300 2019-11-12
Windows 10 MEDIUM 6.8
CVE-2019-1309EPSS 5%

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 6.8
CVE-2019-1310EPSS 5%

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,600 2019-11-12
Enterprise Linux CRITICAL 9.8
CVE-2011-2897

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

Fix: after 2.31.1
Fix from $2,300 2019-11-12
Qpid Cpp MEDIUM 6.5
CVE-2009-5004

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

Mitigation only
Fix from $1,600 2019-11-09
Zxupn 9000e Firmware HIGH 8.8
CVE-2019-3426

The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vulnerability. An attacker could…

Fix: 9000ev5.0r1b12+
Fix from $1,950 2019-11-08
Mod Ruid2 HIGH 7.5
CVE-2013-1889

mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI script to break out of the ch…

Fix: 0.9.8+
Fix from $1,950 2019-11-08
Tuned MEDIUM 5.5
CVE-2013-1820

tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.

Fix: 2.0.2+
Fix from $1,600 2019-11-08
Twiki CRITICAL 9.8
CVE-2013-1751

TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl ba…

Fix: 5.1.4+
Fix from $2,300 2019-11-07
Syscp CRITICAL 9.8
CVE-2010-2476

syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path t…

Patch available
Fix from $2,300 2019-11-07
Gitolite CRITICAL 9.8
CVE-2010-2447

gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

Fix: 1.4.1+
Fix from $2,300 2019-11-07
Gource MEDIUM 6.5
CVE-2010-2449

Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.

Fix: after 0.26
Fix from $1,600 2019-11-07
Drupal MEDIUM 6.5
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was bl…

Fix: 5.22 / 6.16+
Fix from $1,600 2019-11-07
Debian Linux HIGH 7.4
CVE-2012-0051

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

No fix yet
Fix from $1,950 2019-11-07
Linux Kernel HIGH 7.5
CVE-2010-2243

A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /…

Fix: 2.6.33+
Fix from $1,950 2019-11-07
Blink MEDIUM 6.5
CVE-2011-2808

A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.

Mitigation only
Fix from $1,600 2019-11-06
Wpmarketplace HIGH 8.8
CVE-2014-9013EPSS 47%

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arb…

No fix yet
Fix from $1,950 2019-11-06
Konversation HIGH 7.5
CVE-2009-5050

konversation before 1.2.3 allows attackers to cause a denial of service.

Fix: 1.2.3+
Fix from $1,950 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4902

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

Fix: 4.3.12 / 4.4.9+
Fix from $1,600 2019-11-06
TYPO3 MEDIUM 6.5
CVE-2011-4904

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect…

Fix: 4.4.9 / 4.5.4+
Fix from $1,600 2019-11-06
Rbot CRITICAL 9.8
CVE-2010-2446

Rbot Reaction plugin allows command execution

No fix yet
Fix from $2,300 2019-11-06
Firepower Services Software For Asa MEDIUM 5.8
CVE-2019-1978EPSS 9%

A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco F…

Fix: after 2.9.14.5
Fix from $1,600 2019-11-05
Firepower Services Software For Asa MEDIUM 5.8
CVE-2019-1981

A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco F…

Fix: after 2.9.14.5
Fix from $1,600 2019-11-05
Clamav HIGH 7.5
CVE-2019-1789

ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scan…

Fix: 0.101.2+
Fix from $1,950 2019-11-05
Telepresence Advanced Media Gateway HIGH 7.7
CVE-2019-15966

A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial o…

Mitigation only
Fix from $1,950 2019-11-05
TYPO3 MEDIUM 5.3
CVE-2010-3667

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.

Fix: 4.1.14 / 4.2.13+
Fix from $1,600 2019-11-04
Fedora CRITICAL 9.8
CVE-2013-4409

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

Fix: 1.7.15+
Fix from $2,300 2019-11-04
Enterprise Linux CRITICAL 9.8
CVE-2015-8980EPSS 7%

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

Fix: 1.0.12+
Fix from $2,300 2019-11-04