Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Office CRITICAL 9.1
CVE-2019-1109

A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An …

Patch available
Fix from $2,300 2019-07-15
Team Foundation Server CRITICAL 9.8
CVE-2019-1072EPSS 12%

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOp…

Patch available
Fix from $2,300 2019-07-15
Visual Studio MEDIUM 6.5
CVE-2019-1079EPSS 6%

An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Informati…

Patch available
Fix from $1,600 2019-07-15
Windows 10 MEDIUM 6.8
CVE-2019-0966

A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest o…

Patch available
Fix from $1,600 2019-07-15
Op Tee CRITICAL 9.8
CVE-2019-1010295

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The compon…

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Python MEDIUM 5.3
CVE-2018-20852

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be trick…

Fix: 3.4.10 / 3.5.7+
Fix from $1,600 2019-07-13
Xenserver MEDIUM 6.5
CVE-2014-3798

The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted E…

Patch available
Fix from $1,600 2019-07-11
Asa 5506 X Firmware HIGH 8.6
CVE-2019-1873

A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could al…

Mitigation only
Fix from $1,950 2019-07-10
GitLab MEDIUM 5.3
CVE-2018-19580

All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

Fix: 11.3.11 / 11.4.8+
Fix from $1,600 2019-07-10
Proving Grounds HIGH 7.5
CVE-2018-10531

An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application serve…

No fix yet
Fix from $1,950 2019-07-10
PHP HIGH 7.5
CVE-2017-7189

main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the add…

Fix: 7.0.16+
Fix from $1,950 2019-07-10
Libpng CRITICAL 9.8
CVE-2017-12652

libpng before 1.6.32 does not properly check the length of chunks against the user limit.

Fix: 1.6.32+
Fix from $2,300 2019-07-10
Antimalware MEDIUM 5.5
CVE-2018-15738

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…

No fix yet
Fix from $1,600 2019-07-09
Zoom MEDIUM 6.5
CVE-2019-13449

In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?act…

Fix: 4.4.2+
Fix from $1,600 2019-07-09
Kace Systems Management Appliance HIGH 7.2
CVE-2019-10973

Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troublesh…

Fix: after 9.0.270
Fix from $1,950 2019-07-08
Email Security Appliance HIGH 7.4
CVE-2019-1933

A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2019-07-06
Sf200 24 Firmware HIGH 7.5
CVE-2019-1891

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacke…

Fix: 1.4.10.6+
Fix from $1,950 2019-07-06
Enterprise Nfv Infrastructure Software HIGH 7.2
CVE-2019-1894

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges t…

Mitigation only
Fix from $1,950 2019-07-06
Ios Xr MEDIUM 5.9
CVE-2019-1909

A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote …

Fix: 6.6.2+
Fix from $1,600 2019-07-06
Email Security Appliance HIGH 7.5
CVE-2019-1921

A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote …

No fix yet
Fix from $1,950 2019-07-06
Odoo HIGH 7.5
CVE-2018-14733

The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial o…

Mitigation only
Fix from $1,950 2019-07-05
Asyncos HIGH 8.6
CVE-2019-1886

A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a deni…

Fix: 10.5.5-005 / 11.5.2-020+
Fix from $1,950 2019-07-04
Application Policy Infrastructure Controller HIGH 7.2
CVE-2019-1889

A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an a…

Mitigation only
Fix from $1,950 2019-07-04
Asyncos MEDIUM 6.5
CVE-2019-1884

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote …

Fix: 10.5.5-005 / 11.5.2-020+
Fix from $1,600 2019-07-04
Teamcity HIGH 7.5
CVE-2019-12841

Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.

Fix: 2018.2.2+
Fix from $1,950 2019-07-03
Flexpaper CRITICAL 9.8
CVE-2018-11686EPSS 53%

The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

Fix: after 2.3.6
Fix from $2,300 2019-07-03
Draw.io Diagrams MEDIUM 6.1
CVE-2019-13127

An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper …

Fix: 8.3.14+
Fix from $1,600 2019-07-01
Connect Secure HIGH 7.5
CVE-2018-20809

A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX bef…

Mitigation only
Fix from $1,950 2019-06-28
Connect Secure CRITICAL 9.8
CVE-2018-20813

An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.

Mitigation only
Fix from $2,300 2019-06-28
Odoo MEDIUM 6.5
CVE-2018-14887

Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a …

Patch available
Fix from $1,600 2019-06-28