Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 7.8
CVE-2019-5819

Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code vi…

Fix: 74.0.3729.108+
Fix from $1,950 2019-06-27
Chrome HIGH 8.8
CVE-2018-6161

Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted …

Fix: 68.0.3440.75+
Fix from $1,950 2019-06-27
Chrome HIGH 7.8
CVE-2018-6176

Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the rendere…

Fix: 68.0.3440.75+
Fix from $1,950 2019-06-27
Chrome HIGH 8.8
CVE-2018-6121

Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a cra…

Fix: 66.0.3359.170+
Fix from $1,950 2019-06-27
Chrome HIGH 8.1
CVE-2018-6138

Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malici…

Fix: 67.0.3396.62+
Fix from $1,950 2019-06-27
Chrome MEDIUM 6.5
CVE-2017-5028

Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Fix: 56.0.2924.76+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-16064

Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious…

Fix: 68.0.3440.75+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-17460

Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox…

Fix: 68.0.3440.75+
Fix from $1,600 2019-06-27
Openjpeg MEDIUM 6.5
CVE-2018-20846

Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in Ope…

Fix: after 2.3.0
Fix from $1,600 2019-06-26
Libming HIGH 8.8
CVE-2019-12981

Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.

Patch available
Fix from $1,950 2019-06-26
Hoteldruid MEDIUM 6.5
CVE-2019-9085

Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visuali…

Fix: 2.3.1+
Fix from $1,600 2019-06-24
Bluestacks App Player HIGH 8.0
CVE-2019-12936

BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.

Fix: 4.90+
Fix from $1,950 2019-06-23
Antimalware MEDIUM 5.5
CVE-2018-15729

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15730

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15731

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15732

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15734

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15735

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15736

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…

No fix yet
Fix from $1,600 2019-06-21
Antimalware MEDIUM 5.5
CVE-2018-15737

An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin…

No fix yet
Fix from $1,600 2019-06-21
Glot Www CRITICAL 9.8
CVE-2018-15747

The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.syste…

Fix: after 2018-05-19
Fix from $2,300 2019-06-21
Email Security Appliance MEDIUM 5.8
CVE-2019-1905

A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, r…

Mitigation only
Fix from $1,600 2019-06-20
Prime Infrastructure MEDIUM 6.5
CVE-2019-1906

A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual d…

Mitigation only
Fix from $1,600 2019-06-20
Rv110w Firmware HIGH 7.5
CVE-2019-1843

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, …

Fix: 1.0.3.51 / 1.2.2.4+
Fix from $1,950 2019-06-20
Android HIGH 8.8
CVE-2019-2016

In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2019-06-19
Almond 2015 Firmware MEDIUM 6.5
CVE-2017-8330

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devi…

No fix yet
Fix from $1,600 2019-06-18
Weather Microserver Firmware HIGH 7.5
CVE-2018-18878

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attac…

Mitigation only
Fix from $1,950 2019-06-18
Urbackup HIGH 7.5
CVE-2018-20013

In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThr…

Mitigation only
Fix from $1,950 2019-06-18
Mybb HIGH 7.2
CVE-2019-12831

In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a…

Fix: 1.8.21+
Fix from $1,950 2019-06-15
Znc HIGH 8.8
CVE-2019-12816

Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module…

Fix: after 1.7.3
Fix from $1,950 2019-06-15