Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2019-5819 Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code vi… Chrome 74.0.3729.108+ Fix from $1,9502019-06-27 HIGH 8.8 CVE-2018-6161 Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted … Chrome 68.0.3440.75+ Fix from $1,9502019-06-27 HIGH 7.8 CVE-2018-6176 Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the rendere… Chrome 68.0.3440.75+ Fix from $1,9502019-06-27 HIGH 8.8 CVE-2018-6121 Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a cra… Chrome 66.0.3359.170+ Fix from $1,9502019-06-27 HIGH 8.1 CVE-2018-6138 Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malici… Chrome 67.0.3396.62+ Fix from $1,9502019-06-27 MEDIUM 6.5 CVE-2017-5028 Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Chrome 56.0.2924.76+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-16064 Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious… Chrome 68.0.3440.75+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-17460 Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox… Chrome 68.0.3440.75+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-20846 Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in Ope… Openjpeg after 2.3.0 Fix from $1,6002019-06-26 HIGH 8.8 CVE-2019-12981 Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c. Libming Patch available Fix from $1,9502019-06-26 MEDIUM 6.5 CVE-2019-9085 Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visuali… Hoteldruid 2.3.1+ Fix from $1,6002019-06-24 HIGH 8.0 CVE-2019-12936 BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions. Bluestacks App Player 4.90+ Fix from $1,9502019-06-23 MEDIUM 5.5 CVE-2018-15729 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15730 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15731 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15732 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15734 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15735 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15736 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin… Antimalware No fix yet Fix from $1,6002019-06-21 MEDIUM 5.5 CVE-2018-15737 An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validatin… Antimalware No fix yet Fix from $1,6002019-06-21 CRITICAL 9.8 CVE-2018-15747 The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.syste… Glot Www after 2018-05-19 Fix from $2,3002019-06-21 MEDIUM 5.8 CVE-2019-1905 A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, r… Email Security Appliance Mitigation only Fix from $1,6002019-06-20 MEDIUM 6.5 CVE-2019-1906 A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual d… Prime Infrastructure Mitigation only Fix from $1,6002019-06-20 HIGH 7.5 CVE-2019-1843 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, … Rv110w Firmware 1.0.3.51 / 1.2.2.4+ Fix from $1,9502019-06-20 HIGH 8.8 CVE-2019-2016 In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of… Android Mitigation only Fix from $1,9502019-06-19 MEDIUM 6.5 CVE-2017-8330 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devi… Almond 2015 Firmware No fix yet Fix from $1,6002019-06-18 HIGH 7.5 CVE-2018-18878 In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attac… Weather Microserver Firmware Mitigation only Fix from $1,9502019-06-18 HIGH 7.5 CVE-2018-20013 In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThr… Urbackup Mitigation only Fix from $1,9502019-06-18 HIGH 7.2 CVE-2019-12831 In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a… Mybb 1.8.21+ Fix from $1,9502019-06-15 HIGH 8.8 CVE-2019-12816 Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module… Znc after 1.7.3 Fix from $1,9502019-06-15