Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iphone Os HIGH 8.8
CVE-2018-4134

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Safari" component. It allows remote attackers…

Fix: 11.3+
Fix from $1,950 2018-04-03
Iphone Os HIGH 7.5
CVE-2018-4142

An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watch…

Fix: 4.3 / 10.13.4+
Fix from $1,950 2018-04-03
Iphone Os HIGH 8.8
CVE-2018-4149

An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "SafariViewController" component. It allows re…

Fix: 11.3+
Fix from $1,950 2018-04-03
Safari MEDIUM 6.5
CVE-2018-4102

An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attack…

Fix: 11.1+
Fix from $1,600 2018-04-03
Mac Os X CRITICAL 9.8
CVE-2018-4105

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "APFS" component. It allows attackers to …

Fix: 10.13.4+
Fix from $2,300 2018-04-03
Mac Os X MEDIUM 6.5
CVE-2018-4107

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "PDFKit" component. It allows remote atta…

Fix: 10.13.4+
Fix from $1,600 2018-04-03
Mac Os X CRITICAL 9.8
CVE-2018-4108

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Management" component. It allows at…

Fix: 10.13.4+
Fix from $2,300 2018-04-03
Safari MEDIUM 6.5
CVE-2018-4116

An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attack…

Fix: 11.1+
Fix from $1,600 2018-04-03
Mac Os X HIGH 7.8
CVE-2018-4097

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: 10.13.3+
Fix from $1,950 2018-04-03
Iphone Os MEDIUM 5.9
CVE-2017-7164

An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" comp…

Fix: 11.2+
Fix from $1,600 2018-04-03
Mac Os X HIGH 7.8
CVE-2017-7170

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Security" component. It allows attackers…

Fix: 10.13.1+
Fix from $1,950 2018-04-03
Mac Os X HIGH 7.4
CVE-2017-13890

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. macOS before 10.13 is affected. The issue involves the "CoreType…

Fix: 10.13.4+
Fix from $1,950 2018-04-03
Iphone Os MEDIUM 5.5
CVE-2017-7003

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $1,600 2018-04-03
M1033 W Firmware HIGH 7.5
CVE-2018-9158

An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack…

No fix yet
Fix from $1,950 2018-04-01
Android HIGH 7.8
CVE-2017-14892

In the function msm_pcm_hw_params() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-19, the return value of q6asm_open_shared_…

Patch available
Fix from $1,950 2018-03-30
Sanitize HIGH 7.5
CVE-2018-3740

A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.

Fix: after 4.6.0
Fix from $1,950 2018-03-30
Websphere Mq MEDIUM 6.5
CVE-2017-1747

A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications co…

Patch available
Fix from $1,600 2018-03-30
Mdm9206 Firmware CRITICAL 9.8
CVE-2017-14913

In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input validation i…

Mitigation only
Fix from $2,300 2018-03-30
Windriver MEDIUM 5.5
CVE-2018-9136

windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file, a different vuln…

Fix: 12.7.0+
Fix from $1,600 2018-03-30
Samsung Mobile HIGH 7.8
CVE-2018-9141

On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a c…

Mitigation only
Fix from $1,950 2018-03-30
Samsung Mobile HIGH 7.0
CVE-2018-9142

On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation…

Mitigation only
Fix from $1,950 2018-03-30
Exiv2 MEDIUM 6.5
CVE-2018-9145

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may…

No fix yet
Fix from $1,600 2018-03-30
Storage Api CRITICAL 9.8
CVE-2014-5170

The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess…

Mitigation only
Fix from $2,300 2018-03-29
Fisheye HIGH 7.2
CVE-2018-5223

Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider…

Fix: 4.4.6 / 4.5.3+
Fix from $1,950 2018-03-29
Bamboo HIGH 8.8
CVE-2018-5224

Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument para…

Fix: 6.3.3 / 6.4.1+
Fix from $1,950 2018-03-29
Drupal CRITICAL 9.8
CVE-2018-7600 KEVEPSS 100%

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issu…

Fix: 8.3.9 / 8.4.6+
Fix from $2,300 2018-03-29
iOS CRITICAL 9.8
CVE-2018-0171 KEVEPSS 99%

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigg…

Mitigation only
Fix from $2,300 2018-03-28
iOS HIGH 8.6
CVE-2018-0172 KEVEPSS 8%

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, rem…

Mitigation only
Fix from $1,950 2018-03-28
iOS HIGH 8.6
CVE-2018-0173 KEVEPSS 8%

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCP…

Fix: after 15.2
Fix from $1,950 2018-03-28
iOS HIGH 8.6
CVE-2018-0174 KEVEPSS 8%

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, rem…

Fix: after 15.2
Fix from $1,950 2018-03-28