Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Cantata HIGH 8.8
CVE-2018-12561

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as fil…

Fix: after 2.3.1
Fix from $1,950 2018-06-19
Cantata CRITICAL 9.8
CVE-2018-12562

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forw…

Fix: after 2.3.1
Fix from $2,300 2018-06-19
Lava MEDIUM 6.5
CVE-2018-12563

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any …

Fix: 2018.5.post1+
Fix from $1,600 2018-06-19
Debian Linux MEDIUM 6.5
CVE-2018-12564

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that wil…

Fix: 2018.5.post1+
Fix from $1,600 2018-06-19
Debian Linux HIGH 8.8
CVE-2018-12565

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote …

Fix: after 2018.4
Fix from $1,950 2018-06-19
Privileged Access Manager CRITICAL 9.8
CVE-2015-4664EPSS 21%

An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

Fix: after 2.4.4.4
Fix from $2,300 2018-06-18
Privileged Access Manager HIGH 8.8
CVE-2018-9023

An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially cr…

Fix: 3.0.0+
Fix from $1,950 2018-06-18
Privileged Access Manager HIGH 7.5
CVE-2018-9025

An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

Fix: 3.0.0+
Fix from $1,950 2018-06-18
Python HIGH 7.5
CVE-2018-1060EPSS 5%

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker…

Fix: 2.7.15 / 3.4.9+
Fix from $1,950 2018-06-18
Open Xchange Appsuite MEDIUM 6.5
CVE-2018-5753EPSS 8%

The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-re…

Fix: after 7.6.3
Fix from $1,600 2018-06-16
Pandora Fms HIGH 7.5
CVE-2018-11222EPSS 7%

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax …

Fix: after 7.23
Fix from $1,950 2018-06-16
Phpok HIGH 7.5
CVE-2018-12492

PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.

No fix yet
Fix from $1,950 2018-06-15
Debian Linux MEDIUM 6.5
CVE-2018-12458

An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violati…

Patch available
Fix from $1,600 2018-06-15
Ffmpeg MEDIUM 6.5
CVE-2018-12459

An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an asser…

Patch available
Fix from $1,600 2018-06-15
Ua .net Legacy HIGH 8.8
CVE-2017-12070

Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.

Mitigation only
Fix from $1,950 2018-06-14
Ubuntu Linux CRITICAL 9.8
CVE-2018-11574

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,…

Fix: 2.4.9+
Fix from $2,300 2018-06-14
Rfid 181 Eip Firmware HIGH 8.8
CVE-2018-4833

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SI…

Fix: 5.2.3 / 5.4.1+
Fix from $1,950 2018-06-14
Mate 9 Pro Fimware HIGH 7.8
CVE-2017-17173

Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arb…

Mitigation only
Fix from $1,950 2018-06-14
Office MEDIUM 6.5
CVE-2018-8244EPSS 5%

An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation…

Patch available
Fix from $1,600 2018-06-14
Windows 10 HIGH 7.7
CVE-2018-8218EPSS 8%

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged us…

Patch available
Fix from $1,950 2018-06-14
Santricity Storage Manager CRITICAL 9.8
CVE-2018-5488

NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00…

Fix: after 11.42.0x00.0001
Fix from $2,300 2018-06-13
Local Discovery Server MEDIUM 6.5
CVE-2017-17443

OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to trigger a…

Mitigation only
Fix from $1,600 2018-06-13
Booking Calendar HIGH 7.5
CVE-2018-10363

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote a…

Mitigation only
Fix from $1,950 2018-06-13
Android HIGH 7.8
CVE-2018-3582

Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releases from CAF (Android for MSM,…

Patch available
Fix from $1,950 2018-06-12
Linux Kernel MEDIUM 5.5
CVE-2018-5803

In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_…

Fix: 3.2.102 / 4.1.51+
Fix from $1,600 2018-06-12
Sysconfig HIGH 8.1
CVE-2011-4182

Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. …

Fix: after 0.83.7
Fix from $1,950 2018-06-12
Source To Image MEDIUM 6.5
CVE-2018-1103

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user …

Fix: 1.1.10+
Fix from $1,600 2018-06-12
Hana Database HIGH 7.5
CVE-2018-2424

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th…

Mitigation only
Fix from $1,950 2018-06-12
Openshift Container Platform HIGH 7.5
CVE-2018-1070

routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b…

Fix: 3.10+
Fix from $1,950 2018-06-12
Ubuntu Linux MEDIUM 6.1
CVE-2018-5176

The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains maliciou…

Fix: 60.0+
Fix from $1,600 2018-06-11