Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2019-14474 eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to star… Ccu3 Firmware after 3.47.15 Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10812 In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 7.8 CVE-2016-10800 cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138). Cpanel 56.0.27 / 58.0.4+ Fix from $1,9502019-08-07 HIGH 8.1 CVE-2016-10804 The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 8.8 CVE-2016-10805 cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 MEDIUM 6.5 CVE-2016-10807 cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,6002019-08-07 HIGH 8.8 CVE-2016-10808 In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,9502019-08-07 HIGH 7.2 CVE-2019-1914EPSS 25% A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to pe… Sf 220 24 Firmware 1.1.4.4+ Fix from $1,9502019-08-07 CRITICAL 9.8 CVE-2019-13143 An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user nam… Fb50 Firmware No fix yet Fix from $2,3002019-08-06 HIGH 8.8 CVE-2016-10793 cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). Cpanel 11.52.6.6 / 11.54.0.29+ Fix from $1,9502019-08-06 HIGH 8.8 CVE-2016-10788 cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 HIGH 8.8 CVE-2016-10789 cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 HIGH 8.1 CVE-2016-10787 The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-06 HIGH 8.8 CVE-2017-18475 In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204). Cpanel 11.54.0.36 / 56.0.43+ Fix from $1,9502019-08-05 MEDIUM 6.5 CVE-2017-18482 cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213). Cpanel 11.54.0.36 / 56.0.43+ Fix from $1,6002019-08-05 MEDIUM 6.5 CVE-2016-10768 cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-05 MEDIUM 6.5 CVE-2016-10770 cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-05 HIGH 8.1 CVE-2016-10771 cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,9502019-08-05 MEDIUM 6.5 CVE-2016-10775 cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173). Cpanel 11.54.0.33 / 56.0.39+ Fix from $1,6002019-08-05 MEDIUM 6.3 CVE-2017-18469 cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233). Cpanel 56.0.46 / 58.0.45+ Fix from $1,6002019-08-05 MEDIUM 5.3 CVE-2019-7898 Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 MEDIUM 5.3 CVE-2019-7899 Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Ma… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 HIGH 8.8 CVE-2019-7885 Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, … Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2017-18460 cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221). Cpanel 60.0.39 / 62.0.17+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2017-18463 cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225). Cpanel 56.0.46 / 58.0.45+ Fix from $1,9502019-08-02 MEDIUM 5.5 CVE-2017-18449 cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02 MEDIUM 6.7 CVE-2017-18452 cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02 HIGH 7.8 CVE-2017-18459 cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220). Cpanel 56.0.46 / 58.0.45+ Fix from $1,9502019-08-02 MEDIUM 6.3 CVE-2017-18439 cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02 MEDIUM 5.8 CVE-2017-18443 cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02