Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Security Privileged Identity Manager HIGH 8.8
CVE-2018-1640

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the sys…

Mitigation only
Fix from $1,950 2019-04-02
Sso Server MEDIUM 6.1
CVE-2017-16775

Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers t…

Fix: 2.1.3-0129+
Fix from $1,600 2019-04-01
Libmysofa CRITICAL 9.8
CVE-2019-10672

treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.

Fix: 0.7+
Fix from $2,300 2019-03-31
Blue Sdk HIGH 7.5
CVE-2018-20378

The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow remote, unauthenticated attack…

Fix: 6.0.1+
Fix from $1,950 2019-03-29
Ios Xe HIGH 8.8
CVE-2019-1754

A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to r…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 7.2
CVE-2019-1755

A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execut…

Patch available
Fix from $1,950 2019-03-28
iOS HIGH 7.2
CVE-2019-1756

A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affect…

Patch available
Fix from $1,950 2019-03-28
Ios Xe MEDIUM 5.9
CVE-2019-1760

A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affect…

Patch available
Fix from $1,600 2019-03-28
iOS HIGH 7.5
CVE-2019-1738

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenti…

Patch available
Fix from $1,950 2019-03-28
iOS HIGH 7.5
CVE-2019-1739

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenti…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 8.6
CVE-2019-1740

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenti…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 7.5
CVE-2019-1741

A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 8.8
CVE-2019-1743

A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the fi…

Patch available
Fix from $1,950 2019-03-28
iOS MEDIUM 6.5
CVE-2019-1746

A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticat…

Patch available
Fix from $1,600 2019-03-28
iOS HIGH 8.6
CVE-2019-1747

A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 7.4
CVE-2019-1749

A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 7.4
CVE-2019-1750

A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, …

Patch available
Fix from $1,950 2019-03-28
iOS HIGH 7.5
CVE-2019-1751

A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthenticated, remote attacker to caus…

Patch available
Fix from $1,950 2019-03-28
iOS HIGH 7.5
CVE-2019-1752

A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the de…

Patch available
Fix from $1,950 2019-03-28
Ios Xe HIGH 8.8
CVE-2019-1753

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cis…

Patch available
Fix from $1,950 2019-03-28
Ethernet\/ip Web Server Module 1756 Eweb HIGH 7.5
CVE-2018-19016

Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.00…

Fix: after 5.001
Fix from $1,950 2019-03-27
Solutions Business Manager HIGH 7.5
CVE-2018-19642

Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

Fix: 11.5+
Fix from $1,950 2019-03-27
Ubuntu Linux MEDIUM 6.5
CVE-2019-9917

ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.

Fix: after 1.7.2
Fix from $1,600 2019-03-27
Flatpak CRITICAL 9.0
CVE-2019-10063

Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-522…

Fix: 1.0.8 / 1.2.4+
Fix from $2,300 2019-03-26
Fortiportal CRITICAL 9.8
CVE-2017-7342

A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or co…

Fix: after 4.0.0
Fix from $2,300 2019-03-25
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2017-9376EPSS 7%

ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDe…

Fix: 9.3+
Fix from $1,600 2019-03-25
Ip Phone 8821 Firmware CRITICAL 9.8
CVE-2019-1716

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone…

Fix: 10.3 / 11.0+
Fix from $2,300 2019-03-22
Ip Phone 8800 Firmware HIGH 7.5
CVE-2019-1766

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una…

Fix: 12.5+
Fix from $1,950 2019-03-22
Fedora HIGH 8.8
CVE-2019-3871EPSS 13%

A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user whe…

Fix: 4.0.7 / 4.1.7+
Fix from $1,950 2019-03-21
Bmxnoc0401 Firmware MEDIUM 5.4
CVE-2015-6461

Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNO…

Mitigation only
Fix from $1,600 2019-03-21