Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 HIGH 8.4
CVE-2018-0965EPSS 5%

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2018-09-13
Nuc Kit Firmware HIGH 8.2
CVE-2018-12176

Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information d…

Mitigation only
Fix from $1,950 2018-09-12
Alp L09 Firmware HIGH 7.8
CVE-2018-7923

Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of par…

Fix: 8.0.0.150+
Fix from $1,950 2018-09-12
Leland Al00 Firmware MEDIUM 5.5
CVE-2018-7906

Some Huawei smart phones with software of Leland-AL00 8.0.0.114(C636), Leland-AL00A 8.0.0.171(C00) have a denial of service (DoS) vulnerability. An a…

Mitigation only
Fix from $1,600 2018-09-12
Alp L09 Firmware HIGH 7.8
CVE-2018-7922

Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of par…

Fix: 8.0.0.150+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.1
CVE-2018-6924

In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser…

Fix: 11.1+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.5
CVE-2017-1082

In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological i…

Fix: 11.1+
Fix from $1,950 2018-09-12
Scalance X408 Firmware HIGH 8.6
CVE-2018-13807

A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). Th…

Fix: 4.0.0+
Fix from $1,950 2018-09-12
Hana HIGH 7.5
CVE-2018-2465

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauth…

Mitigation only
Fix from $1,950 2018-09-11
Netweaver HIGH 8.8
CVE-2018-2462

In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML doc…

Mitigation only
Fix from $1,950 2018-09-11
389 Directory Server MEDIUM 6.5
CVE-2018-10935

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Fix: 1.3.8.7 / 1.4.0.14+
Fix from $1,600 2018-09-11
Debian Linux MEDIUM 5.9
CVE-2016-7073

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middl…

Fix: 3.4.11 / 3.7.4+
Fix from $1,600 2018-09-11
Debian Linux MEDIUM 5.9
CVE-2016-7074

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middl…

Fix: 3.4.11 / 4.0.2+
Fix from $1,600 2018-09-11
Debian Linux HIGH 7.5
CVE-2016-7068EPSS 7%

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacke…

Fix: 3.4.11 / 3.7.4+
Fix from $1,950 2018-09-11
Dnsdist HIGH 7.5
CVE-2016-7069

An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is confi…

Fix: after 1.2.0
Fix from $1,950 2018-09-11
Openstack CRITICAL 9.8
CVE-2018-14620

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…

Mitigation only
Fix from $2,300 2018-09-10
Openstack MEDIUM 6.5
CVE-2018-14635

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP add…

Fix: after 12.0.3
Fix from $1,600 2018-09-10
Debian Linux HIGH 7.5
CVE-2016-7072EPSS 6%

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of ser…

Fix: 3.4.11 / 4.0.2+
Fix from $1,950 2018-09-10
Go Ethereum HIGH 7.5
CVE-2018-16733

In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block.

Fix: 1.8.14+
Fix from $1,950 2018-09-08
Currency Converter Script HIGH 7.5
CVE-2018-16454

PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface change) via an inverted comma.

No fix yet
Fix from $1,950 2018-09-07
Group Controller Firmware HIGH 7.5
CVE-2018-15483

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Denial of Service can occur through the open HTTP interface, aka KONE-04.

Fix: 4.6.5+
Fix from $1,950 2018-09-07
Ec Cube Payment Module HIGH 7.2
CVE-2018-0658

Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) version 2.3.17 and earlier, GMO-PG …

Fix: after 3.5.23
Fix from $1,950 2018-09-07
Connect Secure CRITICAL 9.8
CVE-2018-6320

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Poli…

Mitigation only
Fix from $2,300 2018-09-06
Linux Kernel HIGH 7.5
CVE-2018-5391EPSS 32%

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-as…

Fix: after 4.18
Fix from $1,950 2018-09-06
WordPress HIGH 8.8
CVE-2018-1000773EPSS 8%

WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution…

Fix: after 4.9.8
Fix from $1,950 2018-09-06
Enterprise Linux Desktop HIGH 7.5
CVE-2018-14624

A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly u…

Fix: after 1.4.0.16
Fix from $1,950 2018-09-06
WordPress HIGH 8.8
CVE-2017-1000600

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack…

Fix: 4.9+
Fix from $1,950 2018-09-06
Openshift Container Platform MEDIUM 5.3
CVE-2016-1000232

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial…

Fix: after 5.0.7.2
Fix from $1,600 2018-09-05
Ubuntu Linux CRITICAL 9.8
CVE-2018-0502

An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named…

Fix: 5.6+
Fix from $2,300 2018-09-05
Ubuntu Linux CRITICAL 9.8
CVE-2018-13259

An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program n…

Fix: 5.6+
Fix from $2,300 2018-09-05