Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Libreoffice HIGH 7.8
CVE-2019-9847

A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an ex…

Fix: 6.1.6 / 6.2.3+
Fix from $1,950 2019-05-09
TYPO3 HIGH 7.5
CVE-2019-11832

TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image proc…

Fix: 8.7.25 / 9.5.6+
Fix from $1,950 2019-05-09
Android HIGH 7.5
CVE-2019-2051

In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when p…

Mitigation only
Fix from $1,950 2019-05-08
Android HIGH 7.8
CVE-2018-6243

NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead t…

Mitigation only
Fix from $1,950 2019-05-07
Fedora HIGH 8.1
CVE-2019-7443

KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain typ…

Fix: 5.55.0+
Fix from $1,950 2019-05-07
Readyapi HIGH 8.8
CVE-2018-20580EPSS 10%

The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request para…

No fix yet
Fix from $1,950 2019-05-03
Web Security Appliance HIGH 7.5
CVE-2019-1817

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,950 2019-05-03
Email Security Appliance MEDIUM 5.3
CVE-2019-1844

A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacke…

Mitigation only
Fix from $1,600 2019-05-03
Web Security Appliance HIGH 7.8
CVE-2019-1816

A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform c…

Mitigation only
Fix from $1,950 2019-05-03
Adaptive Security Appliance Software HIGH 7.5
CVE-2019-1697

A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software…

Fix: 6.2.3.12 / 6.3.0.3+
Fix from $1,950 2019-05-03
Adaptive Security Appliance Software HIGH 8.6
CVE-2019-1694

A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co…

Fix: 6.2.3.12 / 6.3.0.3+
Fix from $1,950 2019-05-03
Nx Os HIGH 7.8
CVE-2019-1592

A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software c…

Mitigation only
Fix from $1,950 2019-05-03
Application Policy Infrastructure Controller HIGH 7.8
CVE-2019-1682

A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica…

Fix: 4.1+
Fix from $1,950 2019-05-03
Adaptive Security Appliance Software HIGH 7.5
CVE-2019-1687

A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software…

Fix: 6.2.3.12 / 6.3.0.3+
Fix from $1,950 2019-05-03
Dicom Standard HIGH 7.8
CVE-2019-11687

An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The…

Fix: after 2019b
Fix from $1,950 2019-05-02
Phpbb HIGH 7.5
CVE-2019-9826

The fulltext search component in phpBB before 3.2.6 allows Denial of Service.

Fix: after 3.2.5
Fix from $1,950 2019-05-02
Api Connect MEDIUM 6.1
CVE-2018-2015

IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a ma…

Fix: after 2018.4.1.4
Fix from $1,600 2019-05-02
Tar Fs HIGH 7.5
CVE-2018-20835

A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file…

Fix: 1.16.2+
Fix from $1,950 2019-04-30
Ublock Origin CRITICAL 9.0
CVE-2019-11595

In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web servic…

Fix: 0.9.5.15+
Fix from $2,300 2019-04-29
Firefox HIGH 7.5
CVE-2019-9799

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the …

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox MEDIUM 5.3
CVE-2019-9801

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on…

Fix: 60.6 / 66.0+
Fix from $1,600 2019-04-26
Phone Firmware HIGH 7.5
CVE-2018-14994

The Essential Phone Android device with a build fingerprint of essential/mata/mata:8.1.0/OPM1.180104.166/297:user/release-keys contains a pre-install…

No fix yet
Fix from $1,950 2019-04-25
Defiant Firmware HIGH 7.5
CVE-2018-15003

The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Revvl Plus (Coolpad/alchemy/alchemy:7.1.1/143…

No fix yet
Fix from $1,950 2019-04-25
Xperia L1 Firmware MEDIUM 5.5
CVE-2018-14983

The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7.0/43.0.A.6.49/2867558199:user/release-keys contains the android fram…

Mitigation only
Fix from $1,600 2019-04-25
Compass Firmware HIGH 7.5
CVE-2018-14989

The Plum Compass Android device with a build fingerprint of PLUM/c179_hwf_221/c179_hwf_221:6.0/MRA58K/W16.51.5-22:user/release-keys contains a pre-in…

No fix yet
Fix from $1,950 2019-04-25
Defiant Firmware HIGH 7.5
CVE-2018-14990

The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a buil…

No fix yet
Fix from $1,950 2019-04-25
Defiant Firmware CRITICAL 9.8
CVE-2018-14991

The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a buil…

No fix yet
Fix from $2,300 2019-04-25
Mi 5s Firmware HIGH 7.5
CVE-2018-20823

The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEM…

No fix yet
Fix from $1,950 2019-04-25
Libseccomp Golang HIGH 7.5
CVE-2017-18367

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrict…

Fix: after 0.9.0
Fix from $1,950 2019-04-24
Bonobo Git Server HIGH 8.8
CVE-2019-11218

Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenti…

Fix: 6.5.0+
Fix from $1,950 2019-04-24