Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Big Ip Local Traffic Manager HIGH 8.1
CVE-2018-5542

F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server.

Fix: after 13.0.1
Fix from $1,950 2018-07-25
Pivotal Application Service MEDIUM 6.5
CVE-2018-11044

Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.…

Fix: 1.12.26 / 2.0.17+
Fix from $1,600 2018-07-24
Silver Fabric Enabler For Spotfire Web Player MEDIUM 5.4
CVE-2017-3180

Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied in…

Fix: after 7.0.2
Fix from $1,600 2018-07-24
Dnp3 Tcp Firmware HIGH 7.5
CVE-2018-11451

A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for …

Fix: 4.33 / 7.80+
Fix from $1,950 2018-07-23
Dnp3 Tcp Firmware HIGH 7.5
CVE-2018-11452

A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for …

Fix: 4.33 / 7.80+
Fix from $1,950 2018-07-23
Suricata MEDIUM 5.3
CVE-2016-10728

An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it …

Fix: 3.1.2+
Fix from $1,600 2018-07-23
Pydio MEDIUM 6.6
CVE-2018-1999018

Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/Ant…

Fix: after 8.2.1
Fix from $1,600 2018-07-23
Mitmproxy HIGH 8.8
CVE-2018-14505

mitmweb in mitmproxy v4.0.3 allows DNS Rebinding attacks, related to tools/web/app.py.

Patch available
Fix from $1,950 2018-07-22
Wireshark HIGH 7.5
CVE-2018-14438

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which all…

Fix: after 2.6.2
Fix from $1,950 2018-07-20
Certification CRITICAL 9.8
CVE-2018-10870EPSS 6%

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…

Mitigation only
Fix from $2,300 2018-07-19
Aditustoken HIGH 7.5
CVE-2018-12959

The approveAndCall function of a smart contract implementation for Aditus (ADI), an Ethereum ERC20 token, allows attackers to steal assets (e.g., tra…

No fix yet
Fix from $1,950 2018-07-19
Wr840n HIGH 7.5
CVE-2018-14336EPSS 8%

TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.

No fix yet
Fix from $1,950 2018-07-19
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5533

Under certain conditions on F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traff…

Fix: after 12.1.2
Fix from $1,950 2018-07-19
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5534

Under certain conditions on F5 BIG-IP 13.1.0-13.1.0.5, 13.0.0, 12.1.0-12.1.3.1, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL …

Fix: after 13.1.0.5
Fix from $1,950 2018-07-19
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5535

On F5 BIG-IP 14.0.0, 13.0.0-13.1.0, 12.1.0-12.1.3, or 11.5.1-11.6.3 specifically crafted HTTP responses, when processed by a Virtual Server with an a…

Fix: after 13.1.1
Fix from $1,950 2018-07-19
Openshift Container Platform CRITICAL 9.8
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…

Fix: 2.3.1.0 / 2.4.0.0+
Fix from $2,300 2018-07-19
Wireshark HIGH 7.5
CVE-2018-14339

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto…

Fix: after 2.6.1
Fix from $1,950 2018-07-19
Wireshark HIGH 7.5
CVE-2018-14369

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the HTTP2 dissector could crash. This was addressed in epan/dissectors/packet-http2…

Fix: after 2.6.1
Fix from $1,950 2018-07-19
Webex Teams HIGH 8.8
CVE-2018-0387

A vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's …

Mitigation only
Fix from $1,950 2018-07-18
Cloud Services Platform 2100 HIGH 8.8
CVE-2018-0394

A vulnerability in the web upload function of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to obtain restricted s…

Mitigation only
Fix from $1,950 2018-07-18
Vbond Orchestrator HIGH 8.8
CVE-2018-0345

A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute ar…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Vbond Orchestrator CRITICAL 9.8
CVE-2018-0349

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating s…

Fix: 18.3.0+
Fix from $2,300 2018-07-18
Panel Builder 800 HIGH 7.8
CVE-2018-10616

ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a c…

Mitigation only
Fix from $1,950 2018-07-18
Debian Linux CRITICAL 9.8
CVE-2018-14349

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Ubuntu Linux CRITICAL 9.8
CVE-2018-14351

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14361

An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.

Fix: 20180716+
Fix from $2,300 2018-07-17
Openshift MEDIUM 5.3
CVE-2017-15137

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a…

Mitigation only
Fix from $1,600 2018-07-16
Staros HIGH 8.6
CVE-2018-0369

A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could allow an unauthenticated, remo…

Fix: 21.3.15 / 21.5.7+
Fix from $1,950 2018-07-16
Secure Firewall Management Center HIGH 7.5
CVE-2018-0385

A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an un…

Mitigation only
Fix from $1,950 2018-07-16
Geo Mashup CRITICAL 9.8
CVE-2018-14071

The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.

Fix: 1.10.4+
Fix from $2,300 2018-07-16