Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.3 CVE-2014-0091 Foreman has improper input validation which could lead to partial Denial of Service Foreman No fix yet Fix from $1,6002019-12-11 HIGH 7.3 CVE-2013-4245 Orca has arbitrary code execution due to insecure Python module load Debian Linux Mitigation only Fix from $1,9502019-12-11 HIGH 7.8 CVE-2019-1484EPSS 9% A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution… Windows 10 Patch available Fix from $1,9502019-12-10 MEDIUM 6.0 CVE-2019-1470EPSS 6% An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated… Windows 10 Patch available Fix from $1,6002019-12-10 HIGH 8.2 CVE-2019-1471EPSS 8% A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g… Windows 10 Patch available Fix from $1,9502019-12-10 MEDIUM 6.5 CVE-2019-13750 Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a cra… Chrome 79.0.3945.79+ Fix from $1,6002019-12-10 MEDIUM 6.5 CVE-2013-1689 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. Firefox after 19.0.2 Fix from $1,6002019-12-10 HIGH 7.5 CVE-2019-2232 In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service wh… Android Patch available Fix from $1,9502019-12-06 CRITICAL 9.8 CVE-2019-7193 KEVEPSS 14% This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend… Qts Mitigation only Fix from $2,3002019-12-05 HIGH 7.4 CVE-2013-0243 haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections Hs Tls 0.6.1+ Fix from $1,9502019-12-05 MEDIUM 6.5 CVE-2019-11255 Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshot… External Provisioner after 1.2.1 Fix from $1,6002019-12-05 MEDIUM 6.8 CVE-2019-19579 An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce… Fedora after 4.12.1 Fix from $1,6002019-12-04 HIGH 7.5 CVE-2019-17555 The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w… Olingo after 4.6.0 Fix from $1,9502019-12-04 HIGH 8.8 CVE-2016-1000104 A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. Mod Fcgid after 2016-07-07 Fix from $1,9502019-12-03 HIGH 8.1 CVE-2013-2103 OpenShift cartridge allows remote URL retrieval Openshift Mitigation only Fix from $1,9502019-12-03 HIGH 7.8 CVE-2012-4576 FreeBSD: Input Validation Flaw allows local users to gain elevated privileges FreeBSD No fix yet Fix from $1,9502019-12-02 HIGH 7.5 CVE-2019-19396 illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurre… Omnios Mitigation only Fix from $1,9502019-11-29 HIGH 8.1 CVE-2019-5268 Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulne… Cd10 10 Firmware 10.0.2.5 / 10.0.2.6+ Fix from $1,9502019-11-29 MEDIUM 5.9 CVE-2015-1855 verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properl… Ruby 2.1.6 / 2.2.2+ Fix from $1,6002019-11-29 MEDIUM 6.5 CVE-2019-19376 In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input valida… Octopus Deploy 2019.6.14 / 2019.9.8+ Fix from $1,6002019-11-28 HIGH 7.5 CVE-2019-18247 An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.… Relion 650 Firmware after 2.1.0.1 Fix from $1,9502019-11-27 HIGH 7.5 CVE-2019-15705 An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticate… Fortios after 6.2.1 Fix from $1,9502019-11-27 HIGH 8.1 CVE-2012-2248 An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable. Debian Linux Mitigation only Fix from $1,9502019-11-27 HIGH 7.5 CVE-2011-4310 The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles. Cms Made Simple 1.9.4.3+ Fix from $1,9502019-11-26 CRITICAL 9.8 CVE-2011-4120 Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured… Debian Linux 2.10+ Fix from $2,3002019-11-26 MEDIUM 6.7 CVE-2019-15997 A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitra… Dna Spaces\ 2.0+ Fix from $1,6002019-11-26 MEDIUM 6.7 CVE-2019-15986 A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with ro… Unity Express 10.1+ Fix from $1,6002019-11-26 MEDIUM 5.3 CVE-2019-15988 A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticat… Email Security Appliance Firmware after 12.5.0 Fix from $1,6002019-11-26 MEDIUM 6.5 CVE-2019-15276EPSS 46% A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause … Wireless Lan Controller Software 8.10+ Fix from $1,6002019-11-26 HIGH 8.8 CVE-2019-15288 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an… Telepresence Codec 7.3.19 / 9.8.1+ Fix from $1,9502019-11-26