Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2019-9847 A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an ex… Libreoffice 6.1.6 / 6.2.3+ Fix from $1,9502019-05-09 HIGH 7.5 CVE-2019-11832 TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image proc… TYPO3 8.7.25 / 9.5.6+ Fix from $1,9502019-05-09 HIGH 7.5 CVE-2019-2051 In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when p… Android Mitigation only Fix from $1,9502019-05-08 HIGH 7.8 CVE-2018-6243 NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead t… Android Mitigation only Fix from $1,9502019-05-07 HIGH 8.1 CVE-2019-7443 KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain typ… Fedora 5.55.0+ Fix from $1,9502019-05-07 HIGH 8.8 CVE-2018-20580EPSS 10% The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request para… Readyapi No fix yet Fix from $1,9502019-05-03 HIGH 7.5 CVE-2019-1817 A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote atta… Web Security Appliance Mitigation only Fix from $1,9502019-05-03 MEDIUM 5.3 CVE-2019-1844 A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacke… Email Security Appliance Mitigation only Fix from $1,6002019-05-03 HIGH 7.8 CVE-2019-1816 A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform c… Web Security Appliance Mitigation only Fix from $1,9502019-05-03 HIGH 7.5 CVE-2019-1697 A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software… Adaptive Security Appliance Software 6.2.3.12 / 6.3.0.3+ Fix from $1,9502019-05-03 HIGH 8.6 CVE-2019-1694 A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co… Adaptive Security Appliance Software 6.2.3.12 / 6.3.0.3+ Fix from $1,9502019-05-03 HIGH 7.8 CVE-2019-1592 A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software c… Nx Os Mitigation only Fix from $1,9502019-05-03 HIGH 7.8 CVE-2019-1682 A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica… Application Policy Infrastructure Controller 4.1+ Fix from $1,9502019-05-03 HIGH 7.5 CVE-2019-1687 A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software… Adaptive Security Appliance Software 6.2.3.12 / 6.3.0.3+ Fix from $1,9502019-05-03 HIGH 7.8 CVE-2019-11687 An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The… Dicom Standard after 2019b Fix from $1,9502019-05-02 HIGH 7.5 CVE-2019-9826 The fulltext search component in phpBB before 3.2.6 allows Denial of Service. Phpbb after 3.2.5 Fix from $1,9502019-05-02 MEDIUM 6.1 CVE-2018-2015 IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a ma… Api Connect after 2018.4.1.4 Fix from $1,6002019-05-02 HIGH 7.5 CVE-2018-20835 A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file… Tar Fs 1.16.2+ Fix from $1,9502019-04-30 CRITICAL 9.0 CVE-2019-11595 In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web servic… Ublock Origin 0.9.5.15+ Fix from $2,3002019-04-29 HIGH 7.5 CVE-2019-9799 Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the … Firefox 66.0+ Fix from $1,9502019-04-26 MEDIUM 5.3 CVE-2019-9801 Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on… Firefox 60.6 / 66.0+ Fix from $1,6002019-04-26 HIGH 7.5 CVE-2018-14994 The Essential Phone Android device with a build fingerprint of essential/mata/mata:8.1.0/OPM1.180104.166/297:user/release-keys contains a pre-install… Phone Firmware No fix yet Fix from $1,9502019-04-25 HIGH 7.5 CVE-2018-15003 The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Revvl Plus (Coolpad/alchemy/alchemy:7.1.1/143… Defiant Firmware No fix yet Fix from $1,9502019-04-25 MEDIUM 5.5 CVE-2018-14983 The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7.0/43.0.A.6.49/2867558199:user/release-keys contains the android fram… Xperia L1 Firmware Mitigation only Fix from $1,6002019-04-25 HIGH 7.5 CVE-2018-14989 The Plum Compass Android device with a build fingerprint of PLUM/c179_hwf_221/c179_hwf_221:6.0/MRA58K/W16.51.5-22:user/release-keys contains a pre-in… Compass Firmware No fix yet Fix from $1,9502019-04-25 HIGH 7.5 CVE-2018-14990 The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a buil… Defiant Firmware No fix yet Fix from $1,9502019-04-25 CRITICAL 9.8 CVE-2018-14991 The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a buil… Defiant Firmware No fix yet Fix from $2,3002019-04-25 HIGH 7.5 CVE-2018-20823 The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEM… Mi 5s Firmware No fix yet Fix from $1,9502019-04-25 HIGH 7.5 CVE-2017-18367 libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrict… Libseccomp Golang after 0.9.0 Fix from $1,9502019-04-24 HIGH 8.8 CVE-2019-11218 Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenti… Bonobo Git Server 6.5.0+ Fix from $1,9502019-04-24