Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS HIGH 7.5
CVE-2019-12656

A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web s…

Mitigation only
Fix from $1,950 2019-09-25
Ios Xe HIGH 7.5
CVE-2019-12657

A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device …

Mitigation only
Fix from $1,950 2019-09-25
Zxv10 B860a Firmware CRITICAL 9.8
CVE-2019-3416

All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized u…

Fix: after 81511329.1008
Fix from $2,300 2019-09-23
N301 Firmware HIGH 7.5
CVE-2019-16412

In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Prohibition of this zero value i…

No fix yet
Fix from $1,950 2019-09-19
Imdb Widget HIGH 7.5
CVE-2016-10991

The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.

Fix: 1.0.9+
Fix from $1,950 2019-09-17
Wsecure HIGH 8.8
CVE-2016-10960EPSS 9%

The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

Fix: 2.4+
Fix from $1,950 2019-09-16
Mail Masta HIGH 7.5
CVE-2016-10956EPSS 11%

The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

No fix yet
Fix from $1,950 2019-09-16
Simatic Tdc Cp51m1 Firmware HIGH 7.5
CVE-2019-10937

A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could cause a Denial…

Fix: 1.1.7+
Fix from $1,950 2019-09-13
Arubaos CRITICAL 9.8
CVE-2018-7081EPSS 6%

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmi…

Fix: 6.4.4.21 / 6.5.4.13+
Fix from $2,300 2019-09-13
Post Indexer HIGH 8.1
CVE-2016-10948

The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.

Fix: 3.0.6.2+
Fix from $1,950 2019-09-13
Asp.net Core HIGH 8.8
CVE-2019-1302

An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly san…

Patch available
Fix from $1,950 2019-09-11
Team Foundation Server CRITICAL 9.8
CVE-2019-1306EPSS 17%

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Az…

Patch available
Fix from $2,300 2019-09-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-1295EPSS 8%

A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft Shar…

Patch available
Fix from $1,950 2019-09-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-1296EPSS 8%

A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft Shar…

Patch available
Fix from $1,950 2019-09-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-1257EPSS 12%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2019-09-11
Office HIGH 7.8
CVE-2019-1264

A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerab…

Patch available
Fix from $1,950 2019-09-11
Windows 10 MEDIUM 6.2
CVE-2019-0928

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest o…

Patch available
Fix from $1,600 2019-09-11
Rsa Identity Governance And Lifecycle HIGH 8.8
CVE-2019-3760

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerabi…

Mitigation only
Fix from $1,950 2019-09-11
Asterisk HIGH 7.5
CVE-2019-15639EPSS 22%

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a s…

Fix: after 16.5.0
Fix from $1,950 2019-09-09
Once Cell HIGH 7.5
CVE-2019-16141

An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.

Fix: 1.0.1+
Fix from $1,950 2019-09-09
Renderdocs Rs CRITICAL 9.8
CVE-2019-16142

An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatibl…

Fix: 0.5.0+
Fix from $2,300 2019-09-09
Android MEDIUM 6.7
CVE-2019-9446

In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to improper input validation. This could lead …

Mitigation only
Fix from $1,600 2019-09-06
Android MEDIUM 6.7
CVE-2019-9441

In the Android kernel in the mnh driver there is a possible out of bounds write due to improper input validation. This could lead to escalation of pr…

Mitigation only
Fix from $1,600 2019-09-06
Android HIGH 7.8
CVE-2019-9254

In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local es…

Mitigation only
Fix from $1,950 2019-09-05
Finesse HIGH 7.5
CVE-2019-12632

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery …

Mitigation only
Fix from $1,950 2019-09-05
Unified Contact Center Express HIGH 7.5
CVE-2019-12633

A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and c…

Fix: 11.6+
Fix from $1,950 2019-09-05
Jabber HIGH 7.8
CVE-2019-12645

A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authent…

Fix: 12.6+
Fix from $1,950 2019-09-05
Arduino Esp8266 MEDIUM 6.5
CVE-2019-12588

The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count …

Fix: after 3.1.0
Fix from $1,600 2019-09-04
Nx Os HIGH 7.5
CVE-2019-1968

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to un…

Mitigation only
Fix from $1,950 2019-08-30
Nx Os MEDIUM 5.3
CVE-2019-1969

A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software coul…

Mitigation only
Fix from $1,600 2019-08-30