Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Witycms CRITICAL 9.8
CVE-2018-12065

A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (exe…

No fix yet
Fix from $2,300 2018-06-08
Awus036nh Firmware HIGH 7.5
CVE-2018-12041

An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny service by sending specially con…

Mitigation only
Fix from $1,950 2018-06-08
Dedecms HIGH 7.5
CVE-2018-12046

DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and…

Fix: 5.7+
Fix from $1,950 2018-06-08
Unified Computing System HIGH 7.8
CVE-2018-0338

A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att…

Mitigation only
Fix from $1,950 2018-06-07
Unified Communications Manager MEDIUM 6.1
CVE-2018-0355

A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross…

Mitigation only
Fix from $1,600 2018-06-07
Network Services Orchestrator HIGH 8.8
CVE-2018-0274

A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary she…

Fix: after 4.4.2.0
Fix from $1,950 2018-06-07
Adaptive Security Appliance Software HIGH 7.5
CVE-2018-0296 KEVEPSS 100%

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affec…

Fix: 6.1.0 / 6.2.2.3+
Fix from $1,950 2018-06-07
Mixin Deep HIGH 8.8
CVE-2018-3719

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modi…

Fix: 1.3.1+
Fix from $1,950 2018-06-07
Defaults Deep HIGH 8.8
CVE-2018-3723

defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to m…

Fix: 0.2.4+
Fix from $1,950 2018-06-07
Static Eval CRITICAL 9.8
CVE-2017-16226

The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the gl…

Fix: 2.0.0+
Fix from $2,300 2018-06-07
Parsejson HIGH 7.5
CVE-2017-16113

The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.

Fix: after 0.0.3
Fix from $1,950 2018-06-07
Ocularis HIGH 7.5
CVE-2018-3852

An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet ca…

No fix yet
Fix from $1,950 2018-06-06
Loggregator MEDIUM 6.8
CVE-2018-1268

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d…

Fix: 89.5 / 96.1+
Fix from $1,600 2018-06-06
Manageengine Applications Manager CRITICAL 9.1
CVE-2018-11808EPSS 6%

Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to del…

Mitigation only
Fix from $2,300 2018-06-06
Debian Linux MEDIUM 5.3
CVE-2017-7653

The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that…

Fix: after 1.4.15
Fix from $1,600 2018-06-05
Monstra Cms CRITICAL 9.8
CVE-2018-11678

plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

No fix yet
Fix from $2,300 2018-06-05
FreeBSD MEDIUM 5.9
CVE-2016-9042

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticate…

No fix yet
Fix from $1,600 2018-06-04
Decamelize HIGH 7.5
CVE-2017-16023

Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to e…

Mitigation only
Fix from $1,950 2018-06-04
Request MEDIUM 5.9
CVE-2017-16026

Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero mem…

Fix: 2.47.0+
Fix from $1,600 2018-06-04
Http Signature HIGH 7.5
CVE-2017-16005

Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, …

Fix: after 0.9.11
Fix from $1,950 2018-06-04
Hapi HIGH 7.5
CVE-2017-16013

hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception…

Fix: after 16.1.0
Fix from $1,950 2018-06-04
Kubernetes MEDIUM 5.5
CVE-2018-1002100

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the c…

Fix: after 1.9.5
Fix from $1,600 2018-06-02
Big Ip Application Acceleration Manager HIGH 7.5
CVE-2018-5513

On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leadi…

Fix: after 13.1.0.4
Fix from $1,950 2018-06-01
Big Ip Application Acceleration Manager MEDIUM 5.9
CVE-2018-5522

On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute…

Fix: after 12.1.2
Fix from $1,600 2018-06-01
Jwt Simple MEDIUM 6.5
CVE-2016-10555

Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the ser…

Fix: after 0.3.0
Fix from $1,600 2018-05-31
Negotiator HIGH 7.5
CVE-2016-10539

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Lan…

Fix: after 0.6.0
Fix from $1,950 2018-05-31
Minimatch HIGH 7.5
CVE-2016-10540

Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(…

Fix: after 3.0.1
Fix from $1,950 2018-05-31
Ws HIGH 7.5
CVE-2016-10542EPSS 8%

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending…

Fix: after 1.1.0
Fix from $1,950 2018-05-31
Call MEDIUM 5.3
CVE-2016-10543

call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty par…

Fix: after 3.0.1
Fix from $1,600 2018-05-31
Uws MEDIUM 5.9
CVE-2016-10544

uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibil…

Fix: after 0.10.8
Fix from $1,600 2018-05-31