Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Modulemd CRITICAL 9.8
CVE-2017-1002157

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

Fix: after 1.3.1
Fix from $2,300 2019-01-10
Winscp HIGH 7.5
CVE-2018-20684

In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwritin…

Fix: after 5.13.7
Fix from $1,950 2019-01-10
Email Security Appliance Firmware HIGH 8.6
CVE-2018-15453

A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of …

Mitigation only
Fix from $1,950 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4032

An exploitable privilege escalation vulnerability exists in the way the CleanMyMac X software improperly validates inputs. An attacker with local acc…

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4033

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access …

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4034

The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with l…

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4035

The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with l…

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4036

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access …

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4037

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access …

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4041

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An …

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4042

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An …

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4043

An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user…

No fix yet
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4044

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An …

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4045

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An …

No fix yet
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4046

An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. A user…

Mitigation only
Fix from $1,600 2019-01-10
Cleanmymac X MEDIUM 5.5
CVE-2018-4047

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An …

Mitigation only
Fix from $1,600 2019-01-10
Gitolite HIGH 8.1
CVE-2018-20683

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" im…

Fix: 3.6.11+
Fix from $1,950 2019-01-10
D2200 Firmware HIGH 7.8
CVE-2018-16185

RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Contr…

Fix: after 3.1.10137.0
Fix from $1,950 2019-01-09
Centum Cs 3000 Firmware HIGH 7.5
CVE-2018-16196

Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 -…

Mitigation only
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6160

JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) …

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6169

Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of…

Fix: 68.0.3440.75+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-6139

Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to …

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6140

Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a use…

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome MEDIUM 5.4
CVE-2018-6110

Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a loc…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-6111

An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary…

Fix: 66.0.3359.117+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6113

Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform dom…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6114

Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security …

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6096

A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker…

Fix: 66.0.3359.117+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-20065

Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without …

Fix: 71.0.3578.80+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-20070

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents o…

Fix: 71.0.3578.80+
Fix from $1,600 2019-01-09