Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ios Xe HIGH 8.6
CVE-2018-0472EPSS 16%

A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA…

Mitigation only
Fix from $1,950 2018-10-05
iOS HIGH 7.4
CVE-2018-0475

A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent…

Mitigation only
Fix from $1,950 2018-10-05
iOS HIGH 8.6
CVE-2018-0485

A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Ro…

Mitigation only
Fix from $1,950 2018-10-05
Ios Xe MEDIUM 6.7
CVE-2018-15368

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell …

Mitigation only
Fix from $1,600 2018-10-05
iOS MEDIUM 6.8
CVE-2018-15369

A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca…

Mitigation only
Fix from $1,600 2018-10-05
Ios Xe HIGH 8.6
CVE-2018-0467

A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to r…

Mitigation only
Fix from $1,950 2018-10-05
Umbrella Enterprise Roaming Client HIGH 7.8
CVE-2018-0438

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administr…

Fix: 2.1.127+
Fix from $1,950 2018-10-05
Data Center Network Manager HIGH 7.2
CVE-2018-0440

A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands …

Fix: 11.0+
Fix from $1,950 2018-10-05
Email Security Appliance MEDIUM 5.3
CVE-2018-0447

A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthen…

Mitigation only
Fix from $1,600 2018-10-05
iOS MEDIUM 6.5
CVE-2018-0197

A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacen…

Mitigation only
Fix from $1,600 2018-10-05
E Series Santricity Os Controller CRITICAL 9.8
CVE-2018-5492

NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remote code execution.

Fix: after 11.40
Fix from $2,300 2018-10-04
Emg 12 Firmware CRITICAL 9.8
CVE-2018-14826EPSS 8%

Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a special…

Fix: after 2.57
Fix from $2,300 2018-10-02
Android MEDIUM 5.5
CVE-2018-9452

In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width calculation. This could lead to remote denial of s…

Patch available
Fix from $1,600 2018-10-02
Cisco Ios Module MEDIUM 6.5
CVE-2018-11750

Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisc…

Fix: 0.4.0+
Fix from $1,600 2018-10-02
Tl Wrn841n Firmware MEDIUM 6.5
CVE-2018-15700

The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP…

Mitigation only
Fix from $1,600 2018-10-01
Tl Wrn841n Firmware MEDIUM 6.5
CVE-2018-15701

The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP…

Mitigation only
Fix from $1,600 2018-10-01
Debian Linux HIGH 7.8
CVE-2015-9268

Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechani…

Fix: 2.49+
Fix from $1,950 2018-10-01
Debian Linux MEDIUM 6.5
CVE-2018-16587

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to a…

Fix: 4.0.32 / 5.0.30+
Fix from $1,600 2018-09-28
E Alert Firmware CRITICAL 9.8
CVE-2018-8850

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowing an attacker to craft the i…

Mitigation only
Fix from $2,300 2018-09-26
Chrome HIGH 8.8
CVE-2018-6055

Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary cod…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25
Chrome MEDIUM 6.5
CVE-2018-6119

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome MEDIUM 6.5
CVE-2018-6050

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome HIGH 8.8
CVE-2018-6043

Insufficient data validation in External Protocol Handler in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially execute ar…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25
Chrome MEDIUM 6.1
CVE-2018-6046

Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome MEDIUM 6.5
CVE-2018-6036

Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user data via a crafted HTML…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome MEDIUM 6.1
CVE-2018-6039

Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome MEDIUM 6.5
CVE-2018-6032

Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome HIGH 8.8
CVE-2018-6033

Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25
Coldfusion HIGH 7.5
CVE-2018-15960EPSS 6%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known v…

No fix yet
Fix from $1,950 2018-09-25
Galaxy Apps HIGH 7.8
CVE-2018-10502

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.2. An att…

Fix: 4.2.18.2+
Fix from $1,950 2018-09-24