Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ansi2html HIGH 7.5
CVE-2015-9239

ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

No fix yet
Fix from $1,950 2018-05-31
Jadedown HIGH 7.5
CVE-2016-10520

jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.

Fix: after 0.0.3
Fix from $1,950 2018-05-31
Jshamcrest HIGH 7.5
CVE-2016-10521

jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.

Fix: after 0.7.1
Fix from $1,950 2018-05-31
Ipc Tl Ipc223\(p\) 6 Firmware HIGH 8.8
CVE-2018-11481

TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data be…

Fix: 1.0.21+
Fix from $1,950 2018-05-30
Debian Linux MEDIUM 5.3
CVE-2018-10995

SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

Fix: after 17.02.10.1
Fix from $1,600 2018-05-30
Legacy Ivr Firmware HIGH 8.1
CVE-2018-11518

A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio sign…

Mitigation only
Fix from $1,950 2018-05-30
Eos HIGH 7.5
CVE-2018-11548

An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP ad…

Mitigation only
Fix from $1,950 2018-05-29
Jsonwebtoken CRITICAL 9.8
CVE-2015-9235EPSS 9%

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (…

Fix: 4.2.2+
Fix from $2,300 2018-05-29
Hapi HIGH 7.5
CVE-2015-9241

Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a …

Fix: 11.1.3+
Fix from $1,950 2018-05-29
Ecstatic HIGH 7.5
CVE-2015-9242

Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads …

Fix: 1.4.0+
Fix from $1,950 2018-05-29
Windscribe HIGH 7.8
CVE-2018-11479EPSS 10%

The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishe…

No fix yet
Fix from $1,950 2018-05-25
Moodle HIGH 8.1
CVE-2018-1137

An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who a…

Fix: after 3.4.2
Fix from $1,950 2018-05-25
Dp300 Firmware MEDIUM 5.3
CVE-2017-17315

Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00…

Mitigation only
Fix from $1,600 2018-05-24
Oncommand Unified Manager CRITICAL 9.8
CVE-2018-5487

NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) servic…

Fix: after 7.3
Fix from $2,300 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000040

In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service …

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 5.5
CVE-2018-1000037

In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) vi…

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Dimoncoin HIGH 7.5
CVE-2018-11411

The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attackers to steal assets (e.g., tr…

Mitigation only
Fix from $1,950 2018-05-24
Office For Mac HIGH 8.8
CVE-2018-8176EPSS 23%

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsof…

Patch available
Fix from $1,950 2018-05-23
Wireshark HIGH 7.5
CVE-2018-11354

In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to…

Mitigation only
Fix from $1,950 2018-05-22
Wireshark HIGH 7.5
CVE-2018-11357

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in…

Fix: after 2.4.6
Fix from $1,950 2018-05-22
Hawtio HIGH 7.8
CVE-2017-2617

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file…

Fix: 1.5.5+
Fix from $1,950 2018-05-22
Joomla\! MEDIUM 6.5
CVE-2018-11321

An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulat…

Fix: 3.8.8+
Fix from $1,600 2018-05-22
Cppcms HIGH 7.5
CVE-2018-11367

An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.

Fix: 1.2.1+
Fix from $1,950 2018-05-22
Ct50 Firmware MEDIUM 6.5
CVE-2018-11315

The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can resul…

Fix: after 1.04.84
Fix from $1,600 2018-05-20
Push Notifications HIGH 8.8
CVE-2018-4943EPSS 7%

Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Successful exploitation could l…

Fix: after 1.8.0
Fix from $1,950 2018-05-19
Creative Cloud HIGH 7.8
CVE-2018-4992

Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vulnerability. Successful explo…

Fix: after 4.4.1.298
Fix from $1,950 2018-05-19
Pacsystems Rx3i Cpe305 Firmware HIGH 7.5
CVE-2018-8867

In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP …

Fix: after 9.30
Fix from $1,950 2018-05-18
Linux Kernel MEDIUM 5.5
CVE-2018-11232

The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial o…

Fix: 4.10.2+
Fix from $1,600 2018-05-18
Foxit Reader HIGH 8.8
CVE-2018-9970

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-17
Phantompdf HIGH 8.8
CVE-2018-9935

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is req…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-17