Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux HIGH 8.8
CVE-2018-10929

A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files an…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Enterprise Linux MEDIUM 6.5
CVE-2018-10930

A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination ou…

Fix: 3.12.14 / 4.1.4+
Fix from $1,600 2018-09-04
Virtualization Host HIGH 8.8
CVE-2018-10926

A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to a…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.1
CVE-2018-10927

A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and exec…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host HIGH 8.1
CVE-2018-10923

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker c…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Nomachine CRITICAL 9.8
CVE-2018-0664

A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.

Fix: after 5.0.63
Fix from $2,300 2018-09-04
Pftp HIGH 7.5
CVE-2018-16231

Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified …

Fix: after 8.4f
Fix from $1,950 2018-08-30
Damicms HIGH 7.2
CVE-2018-16238

An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.…

No fix yet
Fix from $1,950 2018-08-30
Linux Kernel HIGH 7.8
CVE-2018-14619

A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_c…

Fix: 4.14.8+
Fix from $1,950 2018-08-30
Mosca HIGH 7.5
CVE-2018-11615

This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required to exploit …

Mitigation only
Fix from $1,950 2018-08-30
Traffic Server HIGH 7.5
CVE-2018-8022EPSS 7%

A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users …

Fix: after 6.2.2
Fix from $1,950 2018-08-29
Traffic Server HIGH 7.5
CVE-2018-1318EPSS 8%

Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server …

Fix: after 7.1.3
Fix from $1,950 2018-08-29
Experience Manager MEDIUM 5.3
CVE-2018-12807

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful exploitation could lead to un…

Fix: after 6.2.1.15
Fix from $1,600 2018-08-29
Chrome MEDIUM 6.5
CVE-2017-15426

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15424

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15425

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homogr…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Chrome MEDIUM 6.5
CVE-2017-15420

Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the con…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Lansweeper CRITICAL 9.8
CVE-2015-9264

Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows servic…

Fix: after 6.0.0.45
Fix from $2,300 2018-08-27
Findme HIGH 7.5
CVE-2018-15885

Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary ana…

No fix yet
Fix from $1,950 2018-08-26
Aspcms CRITICAL 9.8
CVE-2018-15888

An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp page, they can be registered …

No fix yet
Fix from $2,300 2018-08-26
Ajax Bootmodal Login MEDIUM 5.3
CVE-2018-15876

An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require sol…

Mitigation only
Fix from $1,600 2018-08-26
Ubuntu Linux HIGH 7.5
CVE-2018-14598

An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overfl…

Fix: after 1.6.5
Fix from $1,950 2018-08-24
Debian Linux HIGH 8.8
CVE-2018-10858

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use th…

Fix: 4.6.16 / 4.7.9+
Fix from $1,950 2018-08-22
Ubuntu Linux HIGH 8.1
CVE-2018-1139

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A ma…

Fix: 4.7.9 / 4.8.4+
Fix from $1,950 2018-08-22
Samba MEDIUM 6.5
CVE-2018-1140EPSS 11%

A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause …

Fix: 4.8.4+
Fix from $1,600 2018-08-22
Api Connect MEDIUM 5.4
CVE-2018-1599

IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Fix: after 2018.3.4
Fix from $1,600 2018-08-22
Usg2205bsr Firmware HIGH 7.5
CVE-2017-17311

Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnera…

Mitigation only
Fix from $1,950 2018-08-21
Usg2205bsr Firmware HIGH 7.5
CVE-2017-17312

Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnera…

Mitigation only
Fix from $1,950 2018-08-21
Elefantcms CRITICAL 9.8
CVE-2018-15601

apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection …

Patch available
Fix from $2,300 2018-08-21
Satellite HIGH 7.5
CVE-2018-1517

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w…

Mitigation only
Fix from $1,950 2018-08-20