Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Snappy HIGH 8.1
CVE-2018-7577

Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts …

Fix: 1.7.1+
Fix from $1,950 2019-04-24
Gnome Desktop CRITICAL 9.0
CVE-2019-11460

An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may esca…

Fix: 3.30.2.2 / 3.32.1.1+
Fix from $2,300 2019-04-22
Oxide HIGH 7.5
CVE-2016-1586

A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Ox…

Fix: 1.18.3+
Fix from $1,950 2019-04-22
Metal As A Service HIGH 7.5
CVE-2014-1426

A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ub…

Fix: 1.9.2+
Fix from $1,950 2019-04-22
Python Dbusmock HIGH 8.8
CVE-2015-1326

python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing …

Fix: 0.15.1+
Fix from $1,950 2019-04-22
Tv Ip110wn Firmware CRITICAL 9.8
CVE-2019-11417

system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondA…

Mitigation only
Fix from $2,300 2019-04-22
Android HIGH 8.8
CVE-2019-2028

In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional executi…

Patch available
Fix from $1,950 2019-04-19
Satellite HIGH 7.5
CVE-2019-10245

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi…

Fix: 0.14.0+
Fix from $1,950 2019-04-19
Sydent MEDIUM 5.9
CVE-2019-11340

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids opt…

Fix: 1.0.2+
Fix from $1,600 2019-04-19
Catalyst Center HIGH 8.1
CVE-2019-1841

A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal serv…

Fix: 1.2.5+
Fix from $1,950 2019-04-18
Aironet Access Point Firmware MEDIUM 5.7
CVE-2019-1826

A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker t…

Mitigation only
Fix from $1,600 2019-04-18
Email Security Appliance MEDIUM 5.3
CVE-2019-1831

A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remo…

Mitigation only
Fix from $1,600 2019-04-18
Aironet Access Point Firmware MEDIUM 6.5
CVE-2019-1834

A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to ca…

Fix: 8.5.140.0 / 8.8.111.0+
Fix from $1,600 2019-04-18
Unified Communications Manager HIGH 7.5
CVE-2019-1837

A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,950 2019-04-18
Wireless Lan Controller MEDIUM 6.5
CVE-2019-1796

A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthe…

Fix: 8.2.170.0 / 8.5.150.0+
Fix from $1,600 2019-04-18
Wireless Lan Controller MEDIUM 6.5
CVE-2019-1799

A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthe…

Fix: 8.2.170.0 / 8.3.150.0+
Fix from $1,600 2019-04-18
Wireless Lan Controller MEDIUM 6.5
CVE-2019-1800

A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthe…

Fix: 8.2.170.0 / 8.5.150.0+
Fix from $1,600 2019-04-18
Telepresence Video Communication Server MEDIUM 6.5
CVE-2019-1721

A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authentic…

Mitigation only
Fix from $1,600 2019-04-18
Ios Xr CRITICAL 9.8
CVE-2019-1710

A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco IOS XR 64-bit Software could…

Fix: 6.5.3 / 7.0.1+
Fix from $2,300 2019-04-17
Ios Xr HIGH 7.5
CVE-2019-1711

A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a den…

Fix: 6.5.1+
Fix from $1,950 2019-04-17
Ios Xr HIGH 7.5
CVE-2019-1712

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause…

Fix: 6.2.3 / 6.3.2+
Fix from $1,950 2019-04-17
I5 5350u Firmware HIGH 8.2
CVE-2019-0163

Insufficient input validation in system firmware for Intel(R) Broadwell U i5 vPro before version MYBDWi5v.86A may allow an authenticated user to pote…

Patch available
Fix from $1,950 2019-04-17
Shimo Vpn MEDIUM 5.5
CVE-2018-4004

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root u…

No fix yet
Fix from $1,600 2019-04-17
Shimo Vpn HIGH 7.8
CVE-2018-4005

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user …

No fix yet
Fix from $1,950 2019-04-17
Shimo Vpn HIGH 7.8
CVE-2018-4006

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is…

No fix yet
Fix from $1,950 2019-04-17
Shimo Vpn HIGH 7.1
CVE-2018-4007

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is ab…

No fix yet
Fix from $1,950 2019-04-17
Simatic S7 1500 Firmware HIGH 7.5
CVE-2018-16558

A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially…

Fix: 2.5+
Fix from $1,950 2019-04-17
Simatic S7 1500 Firmware HIGH 7.5
CVE-2018-16559

A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially…

Fix: 2.5+
Fix from $1,950 2019-04-17
Simatic S7 300 Firmware HIGH 7.5
CVE-2018-16561

A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets w…

Mitigation only
Fix from $1,950 2019-04-17
Miniblog.core CRITICAL 9.8
CVE-2019-9845

madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because S…

Fix: after 2019-01-16
Fix from $2,300 2019-04-16