Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
FreeBSD HIGH 7.5
CVE-2019-5611

In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.…

Patch available
Fix from $1,950 2019-08-30
Payu India Payment Gateway MEDIUM 5.3
CVE-2019-14978

/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 para…

No fix yet
Fix from $1,600 2019-08-29
Paypal Checkout Payment Gateway MEDIUM 5.3
CVE-2019-14979

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount param…

No fix yet
Fix from $1,600 2019-08-29
Kubernetes HIGH 8.1
CVE-2019-11247

The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.…

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2019-08-29
Suricata HIGH 7.5
CVE-2019-10054

An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memo…

No fix yet
Fix from $1,950 2019-08-28
Nx Os HIGH 7.5
CVE-2019-1962

A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crash…

Fix: 3.2 / 4.0+
Fix from $1,950 2019-08-28
Nx Os MEDIUM 6.5
CVE-2019-1963

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow a…

Fix: 2.2.2.91 / 2.3.1.130+
Fix from $1,600 2019-08-28
Nx Os HIGH 7.5
CVE-2019-1964

A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart…

Fix: 8.2 / 8.4+
Fix from $1,950 2019-08-28
Br 6208ac V1 Firmware HIGH 8.8
CVE-2019-13269

Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device…

No fix yet
Fix from $1,950 2019-08-27
Br 6208ac V1 Firmware HIGH 8.8
CVE-2019-13270

Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device…

No fix yet
Fix from $1,950 2019-08-27
Archer C3200 V1 Firmware HIGH 8.8
CVE-2019-13268

TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are establish…

No fix yet
Fix from $1,950 2019-08-27
Sell Downloads HIGH 7.5
CVE-2015-9348

The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

Fix: 1.0.8+
Fix from $1,950 2019-08-27
Feed Them Social CRITICAL 9.8
CVE-2015-9351

The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.

Fix: 1.7.0+
Fix from $2,300 2019-08-27
Link Log HIGH 7.5
CVE-2015-9345

The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.

Fix: 2.0+
Fix from $1,950 2019-08-27
Cookie HIGH 7.5
CVE-2017-18589

An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.

Fix: 0.7.6+
Fix from $1,950 2019-08-26
Limesurvey HIGH 7.5
CVE-2019-15640

Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.

Fix: 3.17.10+
Fix from $1,950 2019-08-26
Santuario Xml Security For Java MEDIUM 5.5
CVE-2019-12400

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo…

Fix: 2.1.4+
Fix from $1,600 2019-08-23
Pan Os CRITICAL 9.8
CVE-2019-1581

A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access…

Fix: after 9.0.3
Fix from $2,300 2019-08-23
Slidedeck 2 CRITICAL 9.8
CVE-2013-7483

The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

Fix: 2.3.5+
Fix from $2,300 2019-08-22
Wp Support Plus Responsive Ticket System CRITICAL 9.8
CVE-2016-10930

The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

Fix: 7.1.0+
Fix from $2,300 2019-08-22
Apm Agent HIGH 7.2
CVE-2019-7617

When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can cont…

Fix: 5.1.0+
Fix from $1,950 2019-08-22
Ad Inserter HIGH 8.8
CVE-2019-15324

The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.

Fix: 2.4.22+
Fix from $1,950 2019-08-22
Shortcodes Ultimate CRITICAL 9.8
CVE-2017-18580EPSS 12%

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

Fix: 5.0.1+
Fix from $2,300 2019-08-22
Wp Payeezy Pay CRITICAL 9.8
CVE-2018-20985EPSS 8%

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.

Fix: 2.98+
Fix from $2,300 2019-08-22
Memphis Documents Library CRITICAL 9.8
CVE-2014-10383

The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.

Fix: 3.0+
Fix from $2,300 2019-08-22
Memphis Documents Library CRITICAL 9.8
CVE-2014-10384

The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.

Fix: 3.0+
Fix from $2,300 2019-08-22
Ninja Forms MEDIUM 6.1
CVE-2017-18574

The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

Fix: 3.0.31+
Fix from $1,600 2019-08-22
Ninja Forms HIGH 7.5
CVE-2018-20980

The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.

Fix: 3.2.15+
Fix from $1,950 2019-08-22
Ninja Forms CRITICAL 9.1
CVE-2018-20981

The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.

Fix: 3.3.9+
Fix from $2,300 2019-08-22
Google Analyticator MEDIUM 6.1
CVE-2009-5158

The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.

Fix: 5.2.1+
Fix from $1,600 2019-08-22