Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Galaxy S8 Firmware HIGH 8.8
CVE-2018-14318

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S8 G950FXXU1AQL5. User interaction…

Mitigation only
Fix from $1,950 2018-09-24
Samsung Internet Browser HIGH 8.8
CVE-2018-10496

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.1…

Fix: 6.4.0.15+
Fix from $1,950 2018-09-24
Samsung Email HIGH 7.8
CVE-2018-10497

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. An attacker…

Fix: 5.0.02.16+
Fix from $1,950 2018-09-24
Galaxy Apps HIGH 7.0
CVE-2018-10499

This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An …

Fix: 6.4.0.15+
Fix from $1,950 2018-09-24
Couchdb HIGH 7.8
CVE-2018-14889

CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.

Mitigation only
Fix from $1,950 2018-09-21
Webpack Dev Server HIGH 7.5
CVE-2018-14732

An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of reque…

Fix: 3.1.6+
Fix from $1,950 2018-09-21
Hw0021 Firmware MEDIUM 5.9
CVE-2018-13111

There exists a partial Denial of Service vulnerability in Wanscam HW0021 IP Cameras. An attacker could craft a malicious POST request to crash the ON…

Mitigation only
Fix from $1,600 2018-09-21
Uplay HIGH 8.8
CVE-2018-15832

upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to explo…

No fix yet
Fix from $1,950 2018-09-20
Mdm9206 Firmware CRITICAL 9.8
CVE-2018-11287

In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD …

Mitigation only
Fix from $2,300 2018-09-20
Android MEDIUM 5.5
CVE-2018-3574

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace can request ION cache maintenan…

Patch available
Fix from $1,600 2018-09-19
Isilon Onefs HIGH 7.5
CVE-2018-11071

Dell EMC Isilon OneFS versions 7.1.1.x, 7.2.1.x, 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 and Dell EMC IsilonSD Edge versions 8.0.0.x, 8.0.…

Fix: 8.1.2.0+
Fix from $1,950 2018-09-18
Android HIGH 7.8
CVE-2018-11302

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check of input received from user…

Patch available
Fix from $1,950 2018-09-18
Android HIGH 8.0
CVE-2018-11294

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, WLAN handler indication from the firmware…

Patch available
Fix from $1,950 2018-09-18
Android MEDIUM 5.5
CVE-2018-11280

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing user-space there is no s…

Patch available
Fix from $1,600 2018-09-18
Linux Kernel MEDIUM 5.9
CVE-2018-14641

A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to 4.19-rc3 inclusive, which ca…

Patch available
Fix from $1,600 2018-09-18
Webcenter Interaction MEDIUM 6.5
CVE-2018-16956

The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when processing page rename requests. Pa…

Mitigation only
Fix from $1,600 2018-09-18
Moodle MEDIUM 6.1
CVE-2018-14631

moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigat…

Fix: 3.3.8 / 3.4.5+
Fix from $1,600 2018-09-17
Moodle HIGH 8.8
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When imp…

Fix: 3.1.14 / 3.3.8+
Fix from $1,950 2018-09-17
Spamassassin MEDIUM 5.3
CVE-2017-15705EPSS 8%

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags…

Fix: 3.4.2+
Fix from $1,600 2018-09-17
Mesos HIGH 7.5
CVE-2018-1330

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked H…

Fix: 1.4.2 / 1.5.1+
Fix from $1,950 2018-09-13
Bro HIGH 7.5
CVE-2018-17019

In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc.

Fix: after 2.5.5
Fix from $1,950 2018-09-13
Websafe Alert Server HIGH 8.8
CVE-2018-5545

On F5 WebSafe Alert Server 1.0.0-4.2.6, a malicious, authenticated user can execute code on the alert server by using a maliciously crafted payload.

Fix: after 4.2.6
Fix from $1,950 2018-09-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2018-5549

On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing cert…

Fix: after 13.1.0.3
Fix from $1,950 2018-09-13
Lync For Mac HIGH 7.5
CVE-2018-8474EPSS 38%

A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 S…

No fix yet
Fix from $1,950 2018-09-13
Windows 10 MEDIUM 6.2
CVE-2018-8437

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 6.8
CVE-2018-8438EPSS 7%

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,600 2018-09-13
Windows 10 HIGH 8.4
CVE-2018-8439

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2018-09-13
Windows 10 MEDIUM 5.4
CVE-2018-8434

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…

Patch available
Fix from $1,600 2018-09-13
Windows 10 MEDIUM 6.2
CVE-2018-8436

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,600 2018-09-13
.net Framework CRITICAL 9.8
CVE-2018-8421EPSS 29%

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulne…

Patch available
Fix from $2,300 2018-09-13