Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Userwallet HIGH 7.5
CVE-2018-14085

An issue was discovered in a smart contract implementation for UserWallet 0x0a7bca9FB7AfF26c6ED8029BB6f0F5D291587c42, an Ethereum token. First, suppo…

No fix yet
Fix from $1,950 2018-07-16
Virgo Zodiactoken HIGH 7.5
CVE-2018-14089

An issue was discovered in a smart contract implementation for Virgo_ZodiacToken, an Ethereum token. In this contract, 'bool sufficientAllowance = al…

No fix yet
Fix from $1,950 2018-07-16
Debian Linux MEDIUM 6.5
CVE-2018-14055

ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inje…

Fix: after 1.7.0
Fix from $1,600 2018-07-15
Nextgen Gallery HIGH 7.5
CVE-2016-6565

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POS…

Fix: 2.1.57+
Fix from $1,950 2018-07-13
Resident Download Manager CRITICAL 9.8
CVE-2016-6567

SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which according to the reporter may be us…

Mitigation only
Fix from $2,300 2018-07-13
Hn7740s Firmware MEDIUM 6.5
CVE-2016-9494

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The de…

Mitigation only
Fix from $1,600 2018-07-13
Mailman MEDIUM 6.5
CVE-2018-13796

An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

Fix: 2.1.28+
Fix from $1,600 2018-07-12
Codiad CRITICAL 9.8
CVE-2018-14009EPSS 38%

Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.

Fix: after 2.8.4
Fix from $2,300 2018-07-12
Msm8996au Firmware HIGH 7.8
CVE-2017-18155

While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835,…

Mitigation only
Fix from $1,950 2018-07-12
Junos MEDIUM 5.9
CVE-2018-0027

Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash. When RPD is unavailable, routing up…

Mitigation only
Fix from $1,600 2018-07-11
Junos HIGH 7.5
CVE-2018-0032

The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of the same crafted BGP UPDATE can…

Mitigation only
Fix from $1,950 2018-07-11
Junos MEDIUM 5.9
CVE-2018-0034

A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core the JDHCPD daemon by sending…

Mitigation only
Fix from $1,600 2018-07-11
Junos CRITICAL 9.8
CVE-2018-0037

Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION …

Mitigation only
Fix from $2,300 2018-07-11
Couchdb HIGH 7.2
CVE-2018-8007EPSS 12%

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura…

Fix: after 2.1.1
Fix from $1,950 2018-07-11
Lync HIGH 8.8
CVE-2018-8311EPSS 17%

A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, …

Mitigation only
Fix from $1,950 2018-07-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2018-8300EPSS 13%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $1,950 2018-07-11
Visual Studio 2017 HIGH 7.8
CVE-2018-8232

A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tampering Vulnerability." T…

Patch available
Fix from $1,950 2018-07-11
.net Framework HIGH 8.8
CVE-2018-8260EPSS 15%

A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remot…

Mitigation only
Fix from $1,950 2018-07-11
Internet Graphics Server MEDIUM 5.9
CVE-2018-2439

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid…

Mitigation only
Fix from $1,600 2018-07-10
Moodle HIGH 7.3
CVE-2018-10891

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question previ…

Fix: 3.1.13 / 3.3.7+
Fix from $1,950 2018-07-10
Clickshare Cse 200 Firmware HIGH 7.5
CVE-2018-10943

An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP…

Fix: 1.6.0.3+
Fix from $1,950 2018-07-10
Debian Linux MEDIUM 6.5
CVE-2018-10888

A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil…

Fix: 0.27.3+
Fix from $1,600 2018-07-10
Gravity HIGH 7.5
CVE-2018-13795

Gravity before 0.5.1 does not support a maximum recursion depth.

Fix: 0.5.1+
Fix from $1,950 2018-07-09
Floodlight Controller HIGH 7.5
CVE-2018-1000617

Atlassian Floodlight Atlassian Floodlight Controller version 1.2 and earlier versions contains a Denial of Service vulnerability in Forwarding module…

Fix: after 1.2
Fix from $1,950 2018-07-09
Gb Bsi7h 6500 Firmware CRITICAL 9.8
CVE-2017-3197EPSS 6%

GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_B…

No fix yet
Fix from $2,300 2018-07-09
Android HIGH 7.8
CVE-2018-3597

In the ADSP RPC driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch l…

Patch available
Fix from $1,950 2018-07-06
Mercurial HIGH 7.5
CVE-2018-13346

The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the origina…

Fix: 4.6.1+
Fix from $1,950 2018-07-06
Mercurial HIGH 7.5
CVE-2018-13348

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining afte…

Fix: 4.6.1+
Fix from $1,950 2018-07-06
Htcondor MEDIUM 6.5
CVE-2017-16816

The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon cr…

Fix: 8.6.8 / 8.7.5+
Fix from $1,600 2018-07-05
Openshift HIGH 7.5
CVE-2018-10885

In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy …

Fix: 3.10.9+
Fix from $1,950 2018-07-05