Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Sd845 Firmware HIGH 7.8
CVE-2018-11873

Improper input validation leads to buffer overwrite in the WLAN function that handles WLAN roam buffer in Snapdragon Mobile in version SD 845.

Mitigation only
Fix from $1,950 2018-10-29
Sd 845 Firmware HIGH 7.8
CVE-2018-11950

Unapproved TrustZone applications can be loaded and executed in Snapdragon Mobile in version SD 845, SD 850

Mitigation only
Fix from $1,950 2018-10-26
Splunk HIGH 7.5
CVE-2018-7429

Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to…

Fix: 6.2.14 / 6.3.11+
Fix from $1,950 2018-10-23
Splunk HIGH 7.5
CVE-2018-7432

Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote at…

Fix: 6.2.14 / 6.3.10+
Fix from $1,950 2018-10-23
Fastjson CRITICAL 9.8
CVE-2017-18349EPSS 39%

parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary cod…

Fix: 1.2.25+
Fix from $2,300 2018-10-23
Webaccess HIGH 7.5
CVE-2018-14820

Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allo…

Fix: after 8.3.1
Fix from $1,950 2018-10-23
Msm8909w Firmware MEDIUM 5.5
CVE-2017-18292

Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdrag…

Mitigation only
Fix from $1,600 2018-10-23
Ypc99 Firmware MEDIUM 6.5
CVE-2018-13115

Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on…

No fix yet
Fix from $1,600 2018-10-22
Debian Linux HIGH 7.5
CVE-2018-18541

In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker…

Fix: 0.6.5+
Fix from $1,950 2018-10-20
Enterprise Linux Desktop HIGH 7.0
CVE-2018-12385

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile director…

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop CRITICAL 9.1
CVE-2018-12387EPSS 10%

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by…

Patch available
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5156

A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream …

Mitigation only
Fix from $2,300 2018-10-18
Firefox MEDIUM 5.3
CVE-2018-12382

The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade…

No fix yet
Fix from $1,600 2018-10-18
Wireless Lan Controller Software HIGH 7.5
CVE-2018-0443

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software…

Mitigation only
Fix from $1,950 2018-10-17
Nx Os HIGH 8.6
CVE-2018-0378

A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could a…

Mitigation only
Fix from $1,950 2018-10-17
Nx Os HIGH 7.7
CVE-2018-0456

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote …

Mitigation only
Fix from $1,950 2018-10-17
Nx Os MEDIUM 5.3
CVE-2018-0395

A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenti…

Mitigation only
Fix from $1,600 2018-10-17
Wireless Lan Controller Software MEDIUM 5.3
CVE-2018-0416

A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view sy…

Mitigation only
Fix from $1,600 2018-10-17
Junos HIGH 7.5
CVE-2018-0058

Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device to reboot. The issue is speci…

Mitigation only
Fix from $1,950 2018-10-10
Junos MEDIUM 5.9
CVE-2018-0060

An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an attacker to cause a Denial of…

Mitigation only
Fix from $1,600 2018-10-10
Junos HIGH 7.5
CVE-2018-0062

A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service which may prevent other users t…

Mitigation only
Fix from $1,950 2018-10-10
Graphics Driver MEDIUM 6.5
CVE-2018-12153

Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.9
CVE-2018-0050

An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cause RPD to crash. Continued re…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.9
CVE-2018-0051

A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allows an attacker to crash MS-PIC…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.3
CVE-2018-0055

Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband Edge (BBE) environment may res…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.3
CVE-2018-0056

If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between t…

Mitigation only
Fix from $1,600 2018-10-10
Junos HIGH 8.8
CVE-2018-0043

Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution. By c…

Mitigation only
Fix from $1,950 2018-10-10
Junos HIGH 8.8
CVE-2018-0045

Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote …

Mitigation only
Fix from $1,950 2018-10-10
Edge MEDIUM 5.4
CVE-2018-8512

A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain speci…

Patch available
Fix from $1,600 2018-10-10
Windows 10 HIGH 8.4
CVE-2018-8489

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2018-10-10