Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Brave MEDIUM 6.5
CVE-2018-10799

A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by …

Fix: 0.14.0+
Fix from $1,600 2018-05-08
Mp3gain HIGH 7.8
CVE-2018-10776

The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and a…

Fix: after 1.5.2
Fix from $1,950 2018-05-07
Ubuntu Linux MEDIUM 6.5
CVE-2018-0494EPSS 17%

GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

Fix: 1.19.5+
Fix from $1,600 2018-05-06
Jasper HIGH 7.5
CVE-2018-9154

There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of servi…

No fix yet
Fix from $1,950 2018-05-04
389 Directory Server MEDIUM 5.9
CVE-2011-0704

389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modif…

Mitigation only
Fix from $1,600 2018-05-04
Gx440 Firmware HIGH 8.8
CVE-2017-15043

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and…

Fix: 4.4.5 / 4.9+
Fix from $1,950 2018-05-04
Ids 2102 Firmware CRITICAL 9.8
CVE-2018-8869

In Lantech IDS 2102 2.0 and prior, nearly all input fields allow for arbitrary input on the device. A CVSS v3 base score of 9.8 has been calculated; …

Mitigation only
Fix from $2,300 2018-05-04
Webex Meetings Online HIGH 8.8
CVE-2018-0287

A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2018-05-02
Aironet Access Point Software HIGH 8.6
CVE-2018-0234

A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access P…

Mitigation only
Fix from $1,950 2018-05-02
Wireless Lan Controller Software HIGH 7.4
CVE-2018-0235

A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent atta…

Mitigation only
Fix from $1,950 2018-05-02
Secure Access Control System CRITICAL 9.8
CVE-2018-0253EPSS 7%

A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute ar…

Fix: 5.8+
Fix from $2,300 2018-05-02
Webex Business Suite 31 CRITICAL 9.6
CVE-2018-0264

A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker…

Fix: 3.0+
Fix from $2,300 2018-05-02
Ap200 Firmware CRITICAL 9.8
CVE-2018-10578

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.…

Fix: 1.2.9.15 / 2.0.0.10+
Fix from $2,300 2018-05-02
Ansible Tower HIGH 8.8
CVE-2018-1104

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…

Fix: after 3.2.3
Fix from $1,950 2018-05-02
Windows Host Compute Service Shim HIGH 8.6
CVE-2018-8115EPSS 35%

A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while impo…

Fix: 0.6.10+
Fix from $1,950 2018-05-02
Synapse HIGH 7.5
CVE-2018-10657

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, relate…

Fix: 0.28.1+
Fix from $1,950 2018-05-02
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5514

On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual serve…

Fix: after 13.1.0.5
Fix from $1,950 2018-05-02
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5517

On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The co…

Fix: after 13.1.0.5
Fix from $1,950 2018-05-02
Hrsale HIGH 8.8
CVE-2018-10260EPSS 6%

A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.

No fix yet
Fix from $1,950 2018-05-01
Spectrum HIGH 7.5
CVE-2018-6589

CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vecto…

Fix: 10.01.02.ptf_10.1.239 / 10.2.3+
Fix from $1,950 2018-05-01
Openshift HIGH 8.8
CVE-2018-1102

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr…

Patch available
Fix from $1,950 2018-04-30
E5771h 937 Firmware MEDIUM 6.5
CVE-2017-17318

Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937…

Mitigation only
Fix from $1,600 2018-04-30
Blackboard Learn MEDIUM 6.1
CVE-2017-18262

Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shi…

Fix: after 9.1
Fix from $1,600 2018-04-30
Useless Ethereum Token HIGH 7.5
CVE-2018-10468

The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal ass…

No fix yet
Fix from $1,950 2018-04-28
Openpcs 7 HIGH 7.5
CVE-2018-4832

A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS 7 V8.1 (All versions < V8.1 …

Fix: 7.2 / 13+
Fix from $1,950 2018-04-24
Ansible HIGH 8.1
CVE-2016-9587EPSS 18%

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacke…

Fix: 2.1.4 / 2.2.1+
Fix from $1,950 2018-04-24
Ar120 S Firmware HIGH 7.5
CVE-2017-17258

Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C2…

Mitigation only
Fix from $1,950 2018-04-24
Android HIGH 8.8
CVE-2014-0900

The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restriction…

Fix: after 4.4.1
Fix from $1,950 2018-04-20
Rt Ac51u Firmware CRITICAL 9.8
CVE-2018-8826

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N…

Mitigation only
Fix from $2,300 2018-04-20
Asr 5000 Series Software MEDIUM 5.8
CVE-2018-0256

A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,600 2018-04-19