Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2012-4030 Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary… Chamilo Lms 1.8.8.6+ Fix from $1,9502020-01-10 HIGH 8.8 CVE-2014-5092EPSS 7% Status2k allows Remote Command Execution in admin/options/editpl.php. Status2k No fix yet Fix from $1,9502020-01-10 MEDIUM 5.3 CVE-2016-6585 A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduc… Norton Mobile Security 3.16+ Fix from $1,6002020-01-08 CRITICAL 9.8 CVE-2019-19495 The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem vi… Tc7230 Steb Firmware No fix yet Fix from $2,3002020-01-08 MEDIUM 6.5 CVE-2016-6589 A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0. It Management Suite No fix yet Fix from $1,6002020-01-08 HIGH 7.3 CVE-2019-14866 In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro… Enterprise Linux 2.13+ Fix from $1,9502020-01-07 CRITICAL 9.8 CVE-2020-5519 The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App… Openlitespeed 1.6.5+ Fix from $2,3002020-01-06 HIGH 7.8 CVE-2013-3945 The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag. Mrsid 4.37+ Fix from $1,9502020-01-02 CRITICAL 9.8 CVE-2014-0048EPSS 7% An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. Docker 1.5.0+ Fix from $2,3002020-01-02 HIGH 7.5 CVE-2019-9668 An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to cause a denial … Rovinbhandari Ftp after 2012-03-28 Fix from $1,9502019-12-31 CRITICAL 9.8 CVE-2014-5289EPSS 12% Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request. Senkas Kolibri No fix yet Fix from $2,3002019-12-27 CRITICAL 9.8 CVE-2019-20041 wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sa… WordPress 5.3.1+ Fix from $2,3002019-12-27 CRITICAL 9.8 CVE-2019-19398 M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an at… M5 Lite 10 Firmware Mitigation only Fix from $2,3002019-12-26 HIGH 7.5 CVE-2019-5266 Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnera… P30 Firmware Mitigation only Fix from $1,9502019-12-23 MEDIUM 6.5 CVE-2019-19337 A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse … Ceph Storage Mitigation only Fix from $1,6002019-12-23 HIGH 7.5 CVE-2019-15910 An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover Zi… Hg100 Firmware No fix yet Fix from $1,9502019-12-20 HIGH 7.5 CVE-2019-15912 An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust cen… Hg100 Firmware No fix yet Fix from $1,9502019-12-20 HIGH 7.5 CVE-2019-15914 An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin pro… Dgnwg03lm Firmware No fix yet Fix from $1,9502019-12-20 HIGH 7.5 CVE-2019-15915 An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to… Dgnwg03lm Firmware No fix yet Fix from $1,9502019-12-20 HIGH 7.5 CVE-2012-6111 gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function Debian Linux Mitigation only Fix from $1,9502019-12-20 HIGH 7.8 CVE-2012-3409 ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation Debian Linux 99+ Fix from $1,9502019-12-20 HIGH 7.2 CVE-2019-19902 An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives thr… Backdrop Cms 1.13.5 / 1.14.2+ Fix from $1,9502019-12-19 MEDIUM 6.7 CVE-2019-11108 Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable es… Converged Security Management Engine Firmware 12.0.45 / 13.0.10+ Fix from $1,6002019-12-18 MEDIUM 6.8 CVE-2019-11086 Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation… Active Management Technology Firmware 12.0.45+ Fix from $1,6002019-12-18 MEDIUM 6.7 CVE-2019-11087 Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) … Converged Security Management Engine Firmware 3.1.70 / 4.0.20+ Fix from $1,6002019-12-18 HIGH 8.8 CVE-2019-11088 Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user … Active Management Technology Firmware 11.8.70 / 11.11.70+ Fix from $1,9502019-12-18 HIGH 7.8 CVE-2019-11103 Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated us… Converged Security Management Engine Firmware 12.0.45 / 13.0.10+ Fix from $1,9502019-12-18 HIGH 7.8 CVE-2019-11104 Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R… Converged Security Management Engine Firmware 3.1.70 / 4.0.20+ Fix from $1,9502019-12-18 CRITICAL 9.8 CVE-2019-11107 Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escala… Active Management Technology Firmware 12.0.45+ Fix from $2,3002019-12-18 HIGH 8.1 CVE-2019-0131 Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user … Active Management Technology Firmware 11.8.70 / 11.11.70+ Fix from $1,9502019-12-18