Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome MEDIUM 6.5
CVE-2019-5800

Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a cra…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Chrome MEDIUM 6.5
CVE-2019-5801

Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Chrome MEDIUM 6.5
CVE-2019-5803

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content securit…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Chrome MEDIUM 6.5
CVE-2019-5793

Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installatio…

Fix: 73.0.3683.75+
Fix from $1,600 2019-05-23
Manageengine Applications Manager HIGH 8.8
CVE-2017-11740

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon…

No fix yet
Fix from $1,950 2019-05-23
Open Xchange Appsuite HIGH 7.5
CVE-2017-5211

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

Fix: after 7.8.3
Fix from $1,950 2019-05-23
Open Xchange Appsuite MEDIUM 5.3
CVE-2017-8341

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

Fix: after 7.8.3
Fix from $1,600 2019-05-22
Discuz\! HIGH 8.8
CVE-2018-14729EPSS 11%

The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

Fix: after 3.4
Fix from $1,950 2019-05-22
Steam Client MEDIUM 5.4
CVE-2018-12270

In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users int…

Mitigation only
Fix from $1,600 2019-05-20
I915 Firmware HIGH 7.8
CVE-2019-11085

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potenti…

Fix: 5.0+
Fix from $1,950 2019-05-17
Nuc Kit Firmware HIGH 7.8
CVE-2019-11094

Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege,…

Mitigation only
Fix from $1,950 2019-05-17
Garoon HIGH 8.7
CVE-2019-5931

Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.

Fix: after 4.6.3
Fix from $1,950 2019-05-17
Active Management Technology Firmware MEDIUM 6.8
CVE-2019-0092

Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthent…

Fix: 11.8.65 / 11.11.65+
Fix from $1,600 2019-05-17
Graphics Driver MEDIUM 5.5
CVE-2019-0115

Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33…

Mitigation only
Fix from $1,600 2019-05-17
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-0957

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affe…

Patch available
Fix from $1,950 2019-05-16
Windows 10 HIGH 7.8
CVE-2019-0885EPSS 14%

A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution…

Patch available
Fix from $1,950 2019-05-16
Windows 10 MEDIUM 6.8
CVE-2019-0886

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…

Patch available
Fix from $1,600 2019-05-16
Ios Xr HIGH 7.4
CVE-2019-1846

A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software…

Mitigation only
Fix from $1,950 2019-05-16
Nx Os HIGH 8.6
CVE-2019-1858

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow a…

Fix: 2.2.2.91 / 2.3.1.130+
Fix from $1,950 2019-05-16
Evolved Programmable Network Manager CRITICAL 9.8
CVE-2019-1821EPSS 98%

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a…

Fix: 3.0.1 / 3.4.1+
Fix from $2,300 2019-05-16
Evolved Programmable Network Manager HIGH 7.2
CVE-2019-1822

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a…

Fix: 3.0.1 / 3.4.1+
Fix from $1,950 2019-05-16
Evolved Programmable Network Manager HIGH 7.2
CVE-2019-1823

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a…

Fix: 3.0.1 / 3.4.1+
Fix from $1,950 2019-05-16
Sf200 24 Firmware HIGH 7.7
CVE-2019-1806

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Mana…

Fix: 1.4.10.6+
Fix from $1,950 2019-05-15
Nx Os HIGH 7.8
CVE-2019-1726

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted…

Fix: 4.0 / 6.0+
Fix from $1,950 2019-05-15
Nx Os MEDIUM 6.0
CVE-2019-1729

A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, loc…

Fix: 7.0+
Fix from $1,600 2019-05-15
FreeBSD HIGH 7.5
CVE-2019-5598

In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4,…

Patch available
Fix from $1,950 2019-05-15
FreeBSD CRITICAL 9.1
CVE-2019-5597

In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in th…

Patch available
Fix from $2,300 2019-05-15
Ios Xe HIGH 7.2
CVE-2019-1862EPSS 6%

A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands o…

Mitigation only
Fix from $1,950 2019-05-13
Esp Idf MEDIUM 6.4
CVE-2018-18558

An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage …

Fix: 3.0.6+
Fix from $1,600 2019-05-13
Openmrs Module Htmlformentry CRITICAL 9.8
CVE-2017-12795

OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

Patch available
Fix from $2,300 2019-05-10