Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Epia E900 Firmware HIGH 7.5
CVE-2018-20404

ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which ca…

No fix yet
Fix from $1,950 2018-12-26
Pro Face Gp Pro Ex HIGH 8.8
CVE-2018-7832

An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executa…

Fix: after 4.08
Fix from $1,950 2018-12-24
Discuzx MEDIUM 5.9
CVE-2018-20424

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp req…

No fix yet
Fix from $1,600 2018-12-24
Plug MEDIUM 6.5
CVE-2018-1000883

Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. T…

Fix: 1.3.5+
Fix from $1,600 2018-12-20
Cscape HIGH 7.8
CVE-2018-19005

Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be exploited by processing specially…

Fix: 9.80.75.3+
Fix from $1,950 2018-12-20
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-15330

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a pay…

Fix: after 14.0.0.2
Fix from $1,950 2018-12-20
Active Iq Unified Manager MEDIUM 6.5
CVE-2018-1000873

Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes …

Fix: 2.9.8 / 11.2.0.3.23+
Fix from $1,600 2018-12-20
Alpine Linux HIGH 8.8
CVE-2018-1000849

Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) …

Fix: 2.6.10 / 2.7.6+
Fix from $1,950 2018-12-20
Veraport G3 HIGH 8.8
CVE-2018-5199

In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to malicious file. A remote unauthe…

Mitigation only
Fix from $1,950 2018-12-20
Coherence MEDIUM 6.5
CVE-2018-20301

An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endp…

Fix: 0.5.2+
Fix from $1,600 2018-12-20
Oozie MEDIUM 6.5
CVE-2018-11799

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that result…

Fix: 5.1.0+
Fix from $1,600 2018-12-19
Webaccess\/scada HIGH 7.3
CVE-2018-18999

WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attack…

Mitigation only
Fix from $1,950 2018-12-19
Nifi HIGH 7.5
CVE-2018-17194

When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE …

Fix: after 1.7.1
Fix from $1,950 2018-12-19
Driveragent MEDIUM 5.5
CVE-2018-19522

DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffer containing user defined con…

No fix yet
Fix from $1,600 2018-12-18
Debian Linux MEDIUM 6.5
CVE-2018-20189

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is…

Patch available
Fix from $1,600 2018-12-17
Printeron MEDIUM 6.5
CVE-2018-19936

PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion.

No fix yet
Fix from $1,600 2018-12-17
Singularity HIGH 7.8
CVE-2018-19295

Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.

Fix: after 2.6.0
Fix from $1,950 2018-12-17
Gvisor MEDIUM 5.5
CVE-2018-20168

Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a den…

Fix: 2018-08-22+
Fix from $1,600 2018-12-17
I Doit HIGH 7.2
CVE-2018-20159EPSS 10%

i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with …

No fix yet
Fix from $1,950 2018-12-15
Wp Maintenance Mode HIGH 7.2
CVE-2018-20156

The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throug…

Fix: 2.0.7+
Fix from $1,950 2018-12-14
WordPress MEDIUM 6.5
CVE-2018-20152

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

Fix: 4.9.9 / 5.0.1+
Fix from $1,600 2018-12-14
Db2 MEDIUM 6.5
CVE-2018-1977

IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user c…

Patch available
Fix from $1,600 2018-12-14
Go HIGH 8.1
CVE-2018-16873EPSS 66%

In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the impo…

Fix: 1.10.6 / 1.11.3+
Fix from $1,950 2018-12-14
Go HIGH 8.1
CVE-2018-16874EPSS 5%

In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malic…

Fix: 1.10.6 / 1.11.3+
Fix from $1,950 2018-12-14
Go HIGH 7.5
CVE-2018-16875EPSS 6%

The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which m…

Fix: 1.10.6 / 1.11.3+
Fix from $1,950 2018-12-14
Simatic Hmi Comfort Panels Firmware HIGH 8.8
CVE-2018-13814

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All ver…

Fix: 14.0+
Fix from $1,950 2018-12-13
Simatic S7 400 Firmware HIGH 7.5
CVE-2018-16556

A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-40…

Fix: 8.2.1+
Fix from $1,950 2018-12-13
Zzzphp HIGH 7.5
CVE-2018-20127

An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension…

No fix yet
Fix from $1,950 2018-12-13
Bigfix Platform MEDIUM 6.1
CVE-2018-1478

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuadi…

Fix: after 9.5.9
Fix from $1,600 2018-12-12
Sharepoint Enterprise Server HIGH 8.8
CVE-2018-8635EPSS 6%

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request…

Patch available
Fix from $1,950 2018-12-12