Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Teamcity CRITICAL 9.8
CVE-2019-12157

In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.

Fix: 2018.2.5+
Fix from $2,300 2019-10-02
Security Manager CRITICAL 9.8
CVE-2019-12630EPSS 66%

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitr…

Fix: 4.18+
Fix from $2,300 2019-10-02
Mdm9150 Firmware HIGH 7.8
CVE-2019-10501

Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer…

Patch available
Fix from $1,950 2019-09-30
Mdm9206 Firmware HIGH 7.8
CVE-2019-10506

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could…

Patch available
Fix from $1,950 2019-09-30
Msm8909w Firmware CRITICAL 9.8
CVE-2019-10538

Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HL…

Patch available
Fix from $2,300 2019-09-30
Simple Form CRITICAL 9.8
CVE-2019-16676

Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked …

Fix: 5.0+
Fix from $2,300 2019-09-30
Fedora MEDIUM 6.5
CVE-2019-9433

In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no addi…

Mitigation only
Fix from $1,600 2019-09-27
Android HIGH 7.5
CVE-2019-9432

In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure in the Blueto…

Mitigation only
Fix from $1,950 2019-09-27
Android MEDIUM 5.9
CVE-2019-9414

In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary…

Mitigation only
Fix from $1,600 2019-09-27
Android MEDIUM 6.5
CVE-2019-9418

In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additio…

Mitigation only
Fix from $1,600 2019-09-27
Android HIGH 7.5
CVE-2019-9393

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9394

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9395

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9396

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9397

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9398

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9401

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9402

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android HIGH 7.5
CVE-2019-9404

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional …

Mitigation only
Fix from $1,950 2019-09-27
Android MEDIUM 6.5
CVE-2019-9379

In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additio…

Mitigation only
Fix from $1,600 2019-09-27
Fedora MEDIUM 6.5
CVE-2019-9371

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional e…

Mitigation only
Fix from $1,600 2019-09-27
Android MEDIUM 6.5
CVE-2019-9348

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…

Mitigation only
Fix from $1,600 2019-09-27
Android MEDIUM 6.5
CVE-2019-9352

In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additio…

Mitigation only
Fix from $1,600 2019-09-27
Android MEDIUM 6.5
CVE-2019-9283

In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additiona…

Mitigation only
Fix from $1,600 2019-09-27
Subversion MEDIUM 6.5
CVE-2018-11782

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only …

Fix: after 1.11.1
Fix from $1,600 2019-09-26
Bj Lazy Load HIGH 7.5
CVE-2015-9415

The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

Fix: 1.0+
Fix from $1,950 2019-09-26
Ios Xe HIGH 8.6
CVE-2019-12663

A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthentic…

Mitigation only
Fix from $1,950 2019-09-25
iOS HIGH 7.5
CVE-2019-12669

A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Software, could allow an unauthenti…

Mitigation only
Fix from $1,950 2019-09-25
Ios Xe HIGH 7.5
CVE-2019-12653

A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of a…

Mitigation only
Fix from $1,950 2019-09-25
iOS HIGH 7.5
CVE-2019-12655

A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT IPv6 to IPv4 (NAT64), and the…

Fix: 16.3.8 / 16.11.1+
Fix from $1,950 2019-09-25