Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2019-5800 Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a cra… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 MEDIUM 6.5 CVE-2019-5801 Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 MEDIUM 6.5 CVE-2019-5803 Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content securit… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 MEDIUM 6.5 CVE-2019-5793 Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installatio… Chrome 73.0.3683.75+ Fix from $1,6002019-05-23 HIGH 8.8 CVE-2017-11740 In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon… Manageengine Applications Manager No fix yet Fix from $1,9502019-05-23 HIGH 7.5 CVE-2017-5211 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. Open Xchange Appsuite after 7.8.3 Fix from $1,9502019-05-23 MEDIUM 5.3 CVE-2017-8341 Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. Open Xchange Appsuite after 7.8.3 Fix from $1,6002019-05-22 HIGH 8.8 CVE-2018-14729EPSS 11% The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code. Discuz\! after 3.4 Fix from $1,9502019-05-22 MEDIUM 5.4 CVE-2018-12270 In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users int… Steam Client Mitigation only Fix from $1,6002019-05-20 HIGH 7.8 CVE-2019-11085 Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potenti… I915 Firmware 5.0+ Fix from $1,9502019-05-17 HIGH 7.8 CVE-2019-11094 Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege,… Nuc Kit Firmware Mitigation only Fix from $1,9502019-05-17 HIGH 8.7 CVE-2019-5931 Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors. Garoon after 4.6.3 Fix from $1,9502019-05-17 MEDIUM 6.8 CVE-2019-0092 Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthent… Active Management Technology Firmware 11.8.65 / 11.11.65+ Fix from $1,6002019-05-17 MEDIUM 5.5 CVE-2019-0115 Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33… Graphics Driver Mitigation only Fix from $1,6002019-05-17 HIGH 8.8 CVE-2019-0957 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affe… Sharepoint Enterprise Server Patch available Fix from $1,9502019-05-16 HIGH 7.8 CVE-2019-0885EPSS 14% A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution… Windows 10 Patch available Fix from $1,9502019-05-16 MEDIUM 6.8 CVE-2019-0886 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated… Windows 10 Patch available Fix from $1,6002019-05-16 HIGH 7.4 CVE-2019-1846 A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software… Ios Xr Mitigation only Fix from $1,9502019-05-16 HIGH 8.6 CVE-2019-1858 A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow a… Nx Os 2.2.2.91 / 2.3.1.130+ Fix from $1,9502019-05-16 CRITICAL 9.8 CVE-2019-1821EPSS 98% A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a… Evolved Programmable Network Manager 3.0.1 / 3.4.1+ Fix from $2,3002019-05-16 HIGH 7.2 CVE-2019-1822 A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a… Evolved Programmable Network Manager 3.0.1 / 3.4.1+ Fix from $1,9502019-05-16 HIGH 7.2 CVE-2019-1823 A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could a… Evolved Programmable Network Manager 3.0.1 / 3.4.1+ Fix from $1,9502019-05-16 HIGH 7.7 CVE-2019-1806 A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Mana… Sf200 24 Firmware 1.4.10.6+ Fix from $1,9502019-05-15 HIGH 7.8 CVE-2019-1726 A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted… Nx Os 4.0 / 6.0+ Fix from $1,9502019-05-15 MEDIUM 6.0 CVE-2019-1729 A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, loc… Nx Os 7.0+ Fix from $1,6002019-05-15 HIGH 7.5 CVE-2019-5598 In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4,… FreeBSD Patch available Fix from $1,9502019-05-15 CRITICAL 9.1 CVE-2019-5597 In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in th… FreeBSD Patch available Fix from $2,3002019-05-15 HIGH 7.2 CVE-2019-1862EPSS 6% A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands o… Ios Xe Mitigation only Fix from $1,9502019-05-13 MEDIUM 6.4 CVE-2018-18558 An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage … Esp Idf 3.0.6+ Fix from $1,6002019-05-13 CRITICAL 9.8 CVE-2017-12795 OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation). Openmrs Module Htmlformentry Patch available Fix from $2,3002019-05-10