Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Flask HIGH 7.5
CVE-2018-1000656

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount o…

Fix: 0.12.3+
Fix from $1,950 2018-08-20
Librehealth Ehr HIGH 7.1
CVE-2018-1000647

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial…

No fix yet
Fix from $1,950 2018-08-20
Esp 200 Firmware HIGH 8.8
CVE-2018-15358

An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version…

Mitigation only
Fix from $1,950 2018-08-17
Debian Linux HIGH 8.8
CVE-2018-10873

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check…

Patch available
Fix from $1,950 2018-08-17
Justassembly HIGH 7.8
CVE-2018-15122

An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by deco…

Mitigation only
Fix from $1,950 2018-08-16
Ios Xr HIGH 8.6
CVE-2018-0418

A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow a…

Fix: after 6.3.3_base
Fix from $1,950 2018-08-15
Email Security Appliance HIGH 7.5
CVE-2018-0419

A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker t…

Mitigation only
Fix from $1,950 2018-08-15
Telepresence Video Communication Server HIGH 7.5
CVE-2018-0409

A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Vi…

Mitigation only
Fix from $1,950 2018-08-15
Office For Mac HIGH 7.8
CVE-2018-8412

An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing …

Patch available
Fix from $1,950 2018-08-15
Windows 10 1703 HIGH 8.8
CVE-2018-8414 KEVEPSS 74%

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution V…

Patch available
Fix from $1,950 2018-08-15
Windows 10 HIGH 7.0
CVE-2018-8339

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an ins…

Mitigation only
Fix from $1,950 2018-08-15
Vert.x MEDIUM 5.3
CVE-2018-12537

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed ch…

Fix: after 3.5.1
Fix from $1,600 2018-08-14
Nextcloud Server MEDIUM 5.3
CVE-2018-3776

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

Fix: 11.0.5 / 12.0.3+
Fix from $1,600 2018-08-12
Naukri Clone Script MEDIUM 6.5
CVE-2018-15185

PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PH…

No fix yet
Fix from $1,600 2018-08-10
Virtualization MEDIUM 6.3
CVE-2018-10908

It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…

Fix: 4.20.37+
Fix from $1,600 2018-08-09
Symfony MEDIUM 6.5
CVE-2017-16790

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request…

Fix: after 3.3.12
Fix from $1,600 2018-08-06
Megacryptopolis HIGH 7.5
CVE-2018-13877

The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smar…

Mitigation only
Fix from $1,950 2018-08-06
Aruba Clearpass Policy Manager HIGH 8.8
CVE-2018-7059

Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permissi…

Fix: 6.6.9+
Fix from $1,950 2018-08-06
Ezplayer HIGH 7.8
CVE-2018-14923

A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback.

Mitigation only
Fix from $1,950 2018-08-03
Restforce CRITICAL 9.8
CVE-2018-3777

Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API requests.

Fix: 3.0.0+
Fix from $2,300 2018-08-03
Global Management System CRITICAL 9.8
CVE-2018-9866

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance…

Fix: after 8.1
Fix from $2,300 2018-08-03
Symfony HIGH 7.2
CVE-2018-14774

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 throug…

Fix: after 4.1.2
Fix from $1,950 2018-08-03
Rincewind HIGH 7.5
CVE-2018-14872

An issue was discovered in Rincewind 0.1. A reinstall vulnerability exists because the parameter p of index.php and another file named commonPages.ph…

No fix yet
Fix from $1,950 2018-08-03
Ttembed HIGH 7.5
CVE-2018-10921

Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially lead to corruption of the input…

No fix yet
Fix from $1,950 2018-08-02
Ttembed MEDIUM 5.5
CVE-2018-10922

An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of service condition due to ttembe…

No fix yet
Fix from $1,600 2018-08-02
Knot Resolver MEDIUM 6.8
CVE-2018-10920

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

Fix: 2.4.1+
Fix from $1,600 2018-08-02
Whale MEDIUM 5.3
CVE-2018-12448

Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, …

Fix: 1.3.48.4+
Fix from $1,600 2018-08-02
Ceph Storage HIGH 7.5
CVE-2016-9579

A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re…

Patch available
Fix from $1,950 2018-08-01
Distribution For Python HIGH 7.8
CVE-2018-3650

Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypas…

Fix: 2018+
Fix from $1,950 2018-08-01
Ubuntu Linux MEDIUM 6.5
CVE-2018-10916

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on th…

Fix: after 4.8.3
Fix from $1,600 2018-08-01