Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 MEDIUM 5.5
CVE-2018-8612

A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connec…

Patch available
Fix from $1,600 2018-12-12
Chrome MEDIUM 5.7
CVE-2018-18358

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy re…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome HIGH 8.8
CVE-2018-18347

Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a …

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Chrome MEDIUM 6.5
CVE-2018-18351

Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote atta…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
Chrome HIGH 8.8
CVE-2018-18354

Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launc…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Datapower Gateway MEDIUM 5.5
CVE-2018-1652

IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9,…

Fix: after 9.0.5
Fix from $1,600 2018-12-11
Jooan Ja Q1h Wi Fi Camera Firmware HIGH 7.5
CVE-2018-20051

Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) v…

No fix yet
Fix from $1,950 2018-12-10
Libav MEDIUM 6.5
CVE-2018-20001

In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that …

No fix yet
Fix from $1,600 2018-12-10
Nebula Capsule Projector Firmware HIGH 7.5
CVE-2018-19980

Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system…

No fix yet
Fix from $1,950 2018-12-08
Debian Linux MEDIUM 6.5
CVE-2018-19967

An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen …

Fix: after 4.11.1
Fix from $1,600 2018-12-08
Onionshare HIGH 7.0
CVE-2018-19960

The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging,…

Fix: after 1.3.1
Fix from $1,950 2018-12-07
Amazon Web Services Freertos HIGH 8.1
CVE-2018-16528

Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in pr…

Fix: after 1.3.1
Fix from $1,950 2018-12-06
Android HIGH 7.8
CVE-2018-9547

In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privileg…

Patch available
Fix from $1,950 2018-12-06
I2 Enterprise Insight Analysis MEDIUM 6.1
CVE-2018-1504

IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a…

Mitigation only
Fix from $1,600 2018-12-06
Nvrmini2 Firmware CRITICAL 9.8
CVE-2018-19864EPSS 25%

NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov…

Fix: after 3.9.1
Fix from $2,300 2018-12-05
Chrome HIGH 8.8
CVE-2018-6088

An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox v…

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Chrome MEDIUM 6.5
CVE-2018-6089

A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a r…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop HIGH 7.5
CVE-2018-6101

A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML …

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Chrome MEDIUM 6.5
CVE-2018-6115

Inappropriate setting of the SEE_MASK_FLAG_NO_UI flag in file downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentia…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Fedora HIGH 7.5
CVE-2018-19591EPSS 6%

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socke…

Fix: after 2.28
Fix from $1,950 2018-12-04
Debian Linux HIGH 8.8
CVE-2018-19788EPSS 11%

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

Patch available
Fix from $1,950 2018-12-03
Openlitespeed MEDIUM 6.5
CVE-2018-19791

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the res…

Fix: 1.5.0+
Fix from $1,600 2018-12-03
Zoom CRITICAL 9.8
CVE-2018-15715

Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable…

Fix: 4.1.34801.1116 / 4.1.34814.1119+
Fix from $2,300 2018-11-30
Tl R600vpn Firmware HIGH 7.5
CVE-2018-3948EPSS 23%

An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL…

No fix yet
Fix from $1,950 2018-11-30
Xclarity Integrator MEDIUM 6.5
CVE-2018-9072

In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file…

Fix: 5.5+
Fix from $1,600 2018-11-30
Netwide Assembler MEDIUM 5.5
CVE-2018-19755

There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (o…

No fix yet
Fix from $1,600 2018-11-30
Sales \& Company Management System HIGH 7.5
CVE-2018-19654

An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a compone…

Fix: after 2018-06-06
Fix from $1,950 2018-11-29
Msm8996au Firmware HIGH 7.8
CVE-2017-18317

Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon…

Mitigation only
Fix from $1,950 2018-11-28
Msm8996au Firmware CRITICAL 9.8
CVE-2017-18318

Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12, SD 425, SD 430, SD 450, SD …

Mitigation only
Fix from $2,300 2018-11-28
Terramaster Operating System MEDIUM 5.3
CVE-2018-13361EPSS 17%

User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.

No fix yet
Fix from $1,600 2018-11-27