Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-0594EPSS 12%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2019-03-05
Sharepoint Enterprise Server CRITICAL 9.8
CVE-2019-0604 KEVEPSS 100%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $2,300 2019-03-05
Iphone Os HIGH 7.5
CVE-2019-6219

A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. Processing …

Fix: 5.1.3 / 10.14.3+
Fix from $1,950 2019-03-05
Supportutils HIGH 7.8
CVE-2018-19636

Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides…

Fix: 3.1-5.7.1+
Fix from $1,950 2019-03-05
Supportutils MEDIUM 5.5
CVE-2018-19640

If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638…

Fix: 3.1-5.7.1+
Fix from $1,600 2019-03-05
Cscape HIGH 7.8
CVE-2019-6555

Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an …

Fix: 9.80+
Fix from $1,950 2019-02-28
Firefox HIGH 7.5
CVE-2018-12401

Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lea…

Fix: 63.0+
Fix from $1,950 2019-02-28
Android HIGH 8.8
CVE-2019-1988

In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in s…

Mitigation only
Fix from $1,950 2019-02-28
Ipq8074 Firmware MEDIUM 5.5
CVE-2018-11864

Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna…

Mitigation only
Fix from $1,600 2019-02-25
Mdm9150 Firmware HIGH 7.8
CVE-2018-11931

Improper access to HLOS is possible while transferring memory to CPZ in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Cons…

Mitigation only
Fix from $1,950 2019-02-25
Mdm9650 Firmware CRITICAL 9.1
CVE-2018-11932

Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrago…

Mitigation only
Fix from $2,300 2019-02-25
Mdm9607 Firmware MEDIUM 5.3
CVE-2018-11935

Improper input validation might result in incorrect app id returned to the caller Instead of returning failure in Snapdragon Auto, Snapdragon Compute…

Mitigation only
Fix from $1,600 2019-02-25
Mdm9206 Firmware CRITICAL 9.8
CVE-2018-13904

Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon C…

Mitigation only
Fix from $2,300 2019-02-25
Webex Teams HIGH 7.3
CVE-2019-1689

A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, remote attacker to upload arbitrary files within…

Fix: 3.13.26920+
Fix from $1,950 2019-02-25
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2019-1691

A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexp…

Fix: 6.2.3.4+
Fix from $1,600 2019-02-21
Security Identity Governance And Intelligence MEDIUM 6.1
CVE-2018-1945

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to hijack the clicking action o…

Fix: after 5.2.4.1
Fix from $1,600 2019-02-21
Indexhibit HIGH 8.8
CVE-2019-8954

In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true acti…

No fix yet
Fix from $1,950 2019-02-20
Chrome HIGH 7.8
CVE-2019-5780

Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute J…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5783

Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Inj…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5769

Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker t…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Woocommerce HIGH 7.5
CVE-2018-20782EPSS 10%

The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.

Fix: 1.1.2+
Fix from $1,950 2019-02-17
Advanced Business Application Programming Platform Kernel HIGH 8.1
CVE-2019-0255

SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Serv…

Mitigation only
Fix from $1,950 2019-02-15
Android HIGH 7.8
CVE-2018-6267

NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly validates input that can affec…

No fix yet
Fix from $1,950 2019-02-13
Cp400pb Firmware HIGH 7.8
CVE-2018-19008

The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the…

Fix: after 2.0.7.05
Fix from $1,950 2019-02-13
Airos HIGH 7.5
CVE-2017-0938EPSS 21%

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attack…

Fix: 1.9.7 / 6.0.7+
Fix from $1,950 2019-02-12
Fibrebridge 7500n Firmware HIGH 7.5
CVE-2018-5499

ATTO FibreBridge 7500N firmware version 2.95 is susceptible to a vulnerability which allows attackers to cause a Denial of Service (DoS).

Patch available
Fix from $1,950 2019-02-12
Ipq8074 Firmware HIGH 7.8
CVE-2018-11847

Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kernel and…

Mitigation only
Fix from $1,950 2019-02-11
Satellite CRITICAL 9.8
CVE-2018-12547

In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…

Fix: 0.12.0+
Fix from $2,300 2019-02-11
Satellite CRITICAL 9.8
CVE-2018-12549

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…

Mitigation only
Fix from $2,300 2019-02-11
Workcentre 3655i Firmware HIGH 8.8
CVE-2018-20767

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $1,950 2019-02-10