Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Cxf Fediz HIGH 7.5
CVE-2018-8038EPSS 11%

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response…

Fix: 1.4.4+
Fix from $1,950 2018-07-05
Deap CRITICAL 9.8
CVE-2018-3749

The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can co…

Fix: 1.0.1+
Fix from $2,300 2018-07-03
Deep Extend CRITICAL 9.8
CVE-2018-3750

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacke…

Fix: after 0.5.0
Fix from $2,300 2018-07-03
Merge Recursive CRITICAL 9.8
CVE-2018-3751

The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the att…

Fix: after 0.3.0
Fix from $2,300 2018-07-03
Merge Options CRITICAL 9.8
CVE-2018-3752

The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attac…

Fix: after 1.0.0
Fix from $2,300 2018-07-03
Merge Object CRITICAL 9.8
CVE-2018-3753

The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attac…

Fix: after 1.0.0
Fix from $2,300 2018-07-03
Pan Os MEDIUM 5.5
CVE-2018-9242

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to d…

Fix: after 8.0.9
Fix from $1,600 2018-07-03
Roku Firmware CRITICAL 9.6
CVE-2018-11314

The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and…

Mitigation only
Fix from $2,300 2018-07-03
Sonos Firmware CRITICAL 9.6
CVE-2018-11316

The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device contro…

Mitigation only
Fix from $2,300 2018-07-03
Whale MEDIUM 5.3
CVE-2018-7635

Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, whi…

Fix: 1.0.41.8+
Fix from $1,600 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7777EPSS 32%

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwa…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion CRITICAL 9.8
CVE-2018-7784

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated…

Fix: 1.3.4+
Fix from $2,300 2018-07-03
U.motion Builder MEDIUM 5.3
CVE-2018-7787

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parame…

Fix: 1.3.4+
Fix from $1,600 2018-07-03
Siclock Tc400 Firmware HIGH 8.2
CVE-2018-4851

A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device c…

Mitigation only
Fix from $1,950 2018-07-03
Openshift Container Platform HIGH 8.8
CVE-2018-10843

source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile…

Fix: 3.7.53+
Fix from $1,950 2018-07-02
Zzcms HIGH 7.5
CVE-2018-13056

An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_…

No fix yet
Fix from $1,950 2018-07-02
Mate 9 Pro MEDIUM 6.5
CVE-2017-17175

Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) …

Mitigation only
Fix from $1,600 2018-07-02
Ansible Engine HIGH 7.8
CVE-2018-10874

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…

Mitigation only
Fix from $1,950 2018-07-02
Manageengine Desktop Central HIGH 7.5
CVE-2018-12999EPSS 9%

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web se…

No fix yet
Fix from $1,950 2018-06-29
Greencms HIGH 7.5
CVE-2018-12988

GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI.

No fix yet
Fix from $1,950 2018-06-29
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2018-5528

Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7.

Fix: after 13.1.0.7
Fix from $1,600 2018-06-27
Renderman HIGH 7.5
CVE-2018-3840

A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a netw…

No fix yet
Fix from $1,950 2018-06-26
Websphere Mq MEDIUM 6.5
CVE-2018-1374

An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connect…

Mitigation only
Fix from $1,600 2018-06-26
Joomla\! HIGH 8.8
CVE-2018-12712

An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" functi…

Fix: after 3.8.8
Fix from $1,950 2018-06-26
Fortify Cloudscan MEDIUM 6.5
CVE-2018-1000607

A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to c…

Fix: after 1.5.1
Fix from $1,600 2018-06-26
Topydo HIGH 8.1
CVE-2018-1000523

topydo contains a CWE-20: Improper Input Validation vulnerability in ListFormatParser::parse, file topydo/lib/ListFormat.py line 292 as of d4f843dac7…

Mitigation only
Fix from $1,950 2018-06-26
Prime Jwt HIGH 7.5
CVE-2018-1000531

inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can re…

Fix: after 1.3.0
Fix from $1,950 2018-06-26
Gitlist CRITICAL 9.8
CVE-2018-1000533EPSS 73%

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that ca…

Fix: after 0.6.0
Fix from $2,300 2018-06-26
U Boot MEDIUM 5.5
CVE-2018-1000205

U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This…

Fix: after 2018.07
Fix from $1,600 2018-06-26
Allen Bradley L30erms Firmware HIGH 7.5
CVE-2017-9312

Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service…

Fix: after 30
Fix from $1,950 2018-06-25