Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Mdm9625 Firmware CRITICAL 9.8
CVE-2015-9116

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450,…

Mitigation only
Fix from $2,300 2018-04-18
Mdm9625 Firmware CRITICAL 9.8
CVE-2015-9108

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450,…

Mitigation only
Fix from $2,300 2018-04-18
Sd 425 Firmware CRITICAL 9.8
CVE-2015-9110

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, …

Mitigation only
Fix from $2,300 2018-04-18
Msm8909w Firmware HIGH 7.5
CVE-2014-9986

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MSM8909W, SD 2…

Mitigation only
Fix from $1,950 2018-04-18
Mdm9206 Firmware CRITICAL 9.8
CVE-2014-10051

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, M…

Mitigation only
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5341EPSS 8%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploa…

No fix yet
Fix from $2,300 2018-04-18
Luna Cpap Machine Firmware MEDIUM 6.5
CVE-2017-12701

BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authenticated at…

Fix: 20170701+
Fix from $1,600 2018-04-17
Endpoint Protection HIGH 7.0
CVE-2016-9093

A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user in…

Fix: after 12.1.6
Fix from $1,950 2018-04-16
Endpoint Protection HIGH 7.8
CVE-2016-9094

Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be e…

Fix: after 14.0
Fix from $1,950 2018-04-16
Hatena Bookmark MEDIUM 6.5
CVE-2018-0560

Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to URL display.

Fix: after 3.70
Fix from $1,600 2018-04-16
Debian Linux MEDIUM 5.4
CVE-2017-0366

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2017-0368

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2017-0370

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link par…

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6148

Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of s…

Fix: after 12.1.3
Fix from $1,950 2018-04-13
Linux Kernel MEDIUM 5.5
CVE-2018-10087

The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local …

Fix: 4.13+
Fix from $1,600 2018-04-13
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-5510

On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual s…

Mitigation only
Fix from $1,950 2018-04-13
Website Seller Script HIGH 8.8
CVE-2018-6879

PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify…

No fix yet
Fix from $1,950 2018-04-12
Hot Scripts Clone HIGH 8.8
CVE-2018-6903

PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attack…

No fix yet
Fix from $1,950 2018-04-12
Windriver MEDIUM 5.5
CVE-2018-10071

windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953826DB DeviceIoControl call.

Fix: 12.8.0+
Fix from $1,600 2018-04-12
Windriver MEDIUM 5.5
CVE-2018-10072

windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953827bf DeviceIoControl call.

Fix: 12.7.0+
Fix from $1,600 2018-04-12
Debian Linux HIGH 7.5
CVE-2018-1086

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove th…

Mitigation only
Fix from $1,950 2018-04-12
Windows 10 HIGH 8.8
CVE-2018-1010EPSS 40%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…

Patch available
Fix from $1,950 2018-04-12
Windows 10 HIGH 8.8
CVE-2018-1012EPSS 24%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…

Patch available
Fix from $1,950 2018-04-12
Windows 10 HIGH 8.8
CVE-2018-1013EPSS 24%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…

Patch available
Fix from $1,950 2018-04-12
Windows 10 HIGH 8.8
CVE-2018-1015EPSS 24%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…

Patch available
Fix from $1,950 2018-04-12
Windows 10 HIGH 8.8
CVE-2018-1016EPSS 24%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphi…

Patch available
Fix from $1,950 2018-04-12
Windows 10 MEDIUM 5.3
CVE-2018-0957

An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated…

Patch available
Fix from $1,600 2018-04-12
Datomic HIGH 8.8
CVE-2018-10054EPSS 34%

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.…

Fix: 0.9.5697+
Fix from $1,950 2018-04-11
Junos MEDIUM 6.5
CVE-2018-0017

A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series devices may allow a certain vali…

Fix: after 15.1x49
Fix from $1,600 2018-04-11
Junos MEDIUM 5.9
CVE-2018-0019

A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the mib2d process to crash resulti…

Patch available
Fix from $1,600 2018-04-11