Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Workcentre 3655i Firmware CRITICAL 9.8
CVE-2018-20771

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $2,300 2019-02-10
Meeting Server HIGH 7.5
CVE-2019-1676

A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remot…

Fix: 2.3.9+
Fix from $1,950 2019-02-08
Ps Phpcaptcha Wp CRITICAL 9.8
CVE-2019-7412

The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.

Fix: 1.2.0+
Fix from $2,300 2019-02-05
Networking Os10 HIGH 7.8
CVE-2018-15778

Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-line interface (CLI).

Fix: 10.4.2.1+
Fix from $1,950 2019-02-04
Laquis Scada HIGH 8.8
CVE-2018-18988

LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remot…

Fix: 4.1.0.4150+
Fix from $1,950 2019-02-01
Android HIGH 7.8
CVE-2018-6241

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lea…

Mitigation only
Fix from $1,950 2019-01-31
Spamtitan MEDIUM 5.3
CVE-2018-15136

TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails t…

Fix: 7.01+
Fix from $1,600 2019-01-30
Kappa Firmware MEDIUM 6.5
CVE-2018-19010

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malforme…

Mitigation only
Fix from $1,600 2019-01-28
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Debian Linux HIGH 7.5
CVE-2018-20743

murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote att…

Fix: after 1.2.19
Fix from $1,950 2019-01-25
Postgis HIGH 7.5
CVE-2017-18359

PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demon…

Fix: 2.3.3+
Fix from $1,950 2019-01-25
Enterprise Nfv Infrastructure Software MEDIUM 5.3
CVE-2019-1656

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell o…

Mitigation only
Fix from $1,600 2019-01-24
Vedge 100 Firmware HIGH 7.8
CVE-2019-1648

A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Vedge 100 Firmware HIGH 8.8
CVE-2019-1650

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating s…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Rv320 Firmware HIGH 7.2
CVE-2019-1652 KEVEPSS 96%

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticat…

Fix: 1.4.2.22+
Fix from $1,950 2019-01-24
Airflow HIGH 8.8
CVE-2017-15720

In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.

Fix: after 1.8.2
Fix from $1,950 2019-01-23
Drupal CRITICAL 9.8
CVE-2019-6339EPSS 33%

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built…

Fix: 7.62 / 8.5.9+
Fix from $2,300 2019-01-22
Glibc MEDIUM 5.3
CVE-2016-10739

In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address fol…

Fix: after 2.28
Fix from $1,600 2019-01-21
Mdm9206 Firmware MEDIUM 5.5
CVE-2018-11999

Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9…

Mitigation only
Fix from $1,600 2019-01-18
Mdm9206 Firmware HIGH 7.8
CVE-2018-5869

Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, M…

Mitigation only
Fix from $1,950 2019-01-18
Relion 630 Firmware HIGH 7.5
CVE-2018-20720

ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot)…

Fix: 1.1.0.c0 / 1.2.0.b3+
Fix from $1,950 2019-01-16
Drupal MEDIUM 5.9
CVE-2017-6921

In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if…

Fix: 8.3.4+
Fix from $1,600 2019-01-15
Safari HIGH 8.8
CVE-2018-4213

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe…

Fix: 2.22.0 / 4.3+
Fix from $1,950 2019-01-11
Mac Os X CRITICAL 9.8
CVE-2018-4254

In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with improved input validation.

Fix: 10.13.5+
Fix from $2,300 2019-01-11
Safari HIGH 7.5
CVE-2018-4277

In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in t…

Fix: 4.3.2 / 10.13.6+
Fix from $1,950 2019-01-11
Safari HIGH 8.8
CVE-2018-4207

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe…

Fix: 2.22.0 / 4.3+
Fix from $1,950 2019-01-11
Safari HIGH 8.8
CVE-2018-4208

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe…

Fix: 2.22.0 / 4.3+
Fix from $1,950 2019-01-11
Safari HIGH 8.8
CVE-2018-4209

In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe…

Fix: 2.22.0 / 4.3+
Fix from $1,950 2019-01-11
Iphone Os MEDIUM 6.5
CVE-2017-13891

In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.

Fix: 11.2+
Fix from $1,600 2019-01-11
Asyncos HIGH 8.6
CVE-2018-15460

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthentic…

Fix: 11.0.2-044_md / 11.1.2-023_md+
Fix from $1,950 2019-01-10