Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ccu3 Firmware HIGH 7.5
CVE-2019-14474

eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to star…

Fix: after 3.47.15
Fix from $1,950 2019-08-07
Cpanel HIGH 8.8
CVE-2016-10812

In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,950 2019-08-07
Cpanel HIGH 7.8
CVE-2016-10800

cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).

Fix: 56.0.27 / 58.0.4+
Fix from $1,950 2019-08-07
Cpanel HIGH 8.1
CVE-2016-10804

The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,950 2019-08-07
Cpanel HIGH 8.8
CVE-2016-10805

cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,950 2019-08-07
Cpanel MEDIUM 6.5
CVE-2016-10807

cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,600 2019-08-07
Cpanel HIGH 8.8
CVE-2016-10808

In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,950 2019-08-07
Sf 220 24 Firmware HIGH 7.2
CVE-2019-1914EPSS 25%

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to pe…

Fix: 1.1.4.4+
Fix from $1,950 2019-08-07
Fb50 Firmware CRITICAL 9.8
CVE-2019-13143

An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user nam…

No fix yet
Fix from $2,300 2019-08-06
Cpanel HIGH 8.8
CVE-2016-10793

cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).

Fix: 11.52.6.6 / 11.54.0.29+
Fix from $1,950 2019-08-06
Cpanel HIGH 8.8
CVE-2016-10788

cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,950 2019-08-06
Cpanel HIGH 8.8
CVE-2016-10789

cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,950 2019-08-06
Cpanel HIGH 8.1
CVE-2016-10787

The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,950 2019-08-06
Cpanel HIGH 8.8
CVE-2017-18475

In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).

Fix: 11.54.0.36 / 56.0.43+
Fix from $1,950 2019-08-05
Cpanel MEDIUM 6.5
CVE-2017-18482

cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).

Fix: 11.54.0.36 / 56.0.43+
Fix from $1,600 2019-08-05
Cpanel MEDIUM 6.5
CVE-2016-10768

cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,600 2019-08-05
Cpanel MEDIUM 6.5
CVE-2016-10770

cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,600 2019-08-05
Cpanel HIGH 8.1
CVE-2016-10771

cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,950 2019-08-05
Cpanel MEDIUM 6.5
CVE-2016-10775

cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).

Fix: 11.54.0.33 / 56.0.39+
Fix from $1,600 2019-08-05
Cpanel MEDIUM 6.3
CVE-2017-18469

cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).

Fix: 56.0.46 / 58.0.45+
Fix from $1,600 2019-08-05
Magento MEDIUM 5.3
CVE-2019-7898

Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7899

Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Ma…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Magento HIGH 8.8
CVE-2019-7885

Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, …

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18460

cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).

Fix: 60.0.39 / 62.0.17+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18463

cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).

Fix: 56.0.46 / 58.0.45+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 5.5
CVE-2017-18449

cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.7
CVE-2017-18452

cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18459

cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).

Fix: 56.0.46 / 58.0.45+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18439

cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.8
CVE-2017-18443

cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02