Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2018-20771 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC… Workcentre 3655i Firmware 073.060.048.15000 / 073.190.048.15000+ Fix from $2,3002019-02-10 HIGH 7.5 CVE-2019-1676 A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remot… Meeting Server 2.3.9+ Fix from $1,9502019-02-08 CRITICAL 9.8 CVE-2019-7412 The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values. Ps Phpcaptcha Wp 1.2.0+ Fix from $2,3002019-02-05 HIGH 7.8 CVE-2018-15778 Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-line interface (CLI). Networking Os10 10.4.2.1+ Fix from $1,9502019-02-04 HIGH 8.8 CVE-2018-18988 LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remot… Laquis Scada 4.1.0.4150+ Fix from $1,9502019-02-01 HIGH 7.8 CVE-2018-6241 NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lea… Android Mitigation only Fix from $1,9502019-01-31 MEDIUM 5.3 CVE-2018-15136 TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails t… Spamtitan 7.01+ Fix from $1,6002019-01-30 MEDIUM 6.5 CVE-2018-19010 Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malforme… Kappa Firmware Mitigation only Fix from $1,6002019-01-28 HIGH 7.5 CVE-2018-16889 Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files … Ceph after 13.2.4 Fix from $1,9502019-01-28 HIGH 7.5 CVE-2018-20743 murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote att… Debian Linux after 1.2.19 Fix from $1,9502019-01-25 HIGH 7.5 CVE-2017-18359 PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demon… Postgis 2.3.3+ Fix from $1,9502019-01-25 MEDIUM 5.3 CVE-2019-1656 A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell o… Enterprise Nfv Infrastructure Software Mitigation only Fix from $1,6002019-01-24 HIGH 7.8 CVE-2019-1648 A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges… Vedge 100 Firmware 18.4.0+ Fix from $1,9502019-01-24 HIGH 8.8 CVE-2019-1650 A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating s… Vedge 100 Firmware 18.4.0+ Fix from $1,9502019-01-24 HIGH 7.2 CVE-2019-1652 KEVEPSS 96% A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticat… Rv320 Firmware 1.4.2.22+ Fix from $1,9502019-01-24 HIGH 8.8 CVE-2017-15720 In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object. Airflow after 1.8.2 Fix from $1,9502019-01-23 CRITICAL 9.8 CVE-2019-6339EPSS 33% In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built… Drupal 7.62 / 8.5.9+ Fix from $2,3002019-01-22 MEDIUM 5.3 CVE-2016-10739 In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address fol… Glibc after 2.28 Fix from $1,6002019-01-21 MEDIUM 5.5 CVE-2018-11999 Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9… Mdm9206 Firmware Mitigation only Fix from $1,6002019-01-18 HIGH 7.8 CVE-2018-5869 Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, M… Mdm9206 Firmware Mitigation only Fix from $1,9502019-01-18 HIGH 7.5 CVE-2018-20720 ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot)… Relion 630 Firmware 1.1.0.c0 / 1.2.0.b3+ Fix from $1,9502019-01-16 MEDIUM 5.9 CVE-2017-6921 In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if… Drupal 8.3.4+ Fix from $1,6002019-01-15 HIGH 8.8 CVE-2018-4213 In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe… Safari 2.22.0 / 4.3+ Fix from $1,9502019-01-11 CRITICAL 9.8 CVE-2018-4254 In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with improved input validation. Mac Os X 10.13.5+ Fix from $2,3002019-01-11 HIGH 7.5 CVE-2018-4277 In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in t… Safari 4.3.2 / 10.13.6+ Fix from $1,9502019-01-11 HIGH 8.8 CVE-2018-4207 In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe… Safari 2.22.0 / 4.3+ Fix from $1,9502019-01-11 HIGH 8.8 CVE-2018-4208 In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe… Safari 2.22.0 / 4.3+ Fix from $1,9502019-01-11 HIGH 8.8 CVE-2018-4209 In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpe… Safari 2.22.0 / 4.3+ Fix from $1,9502019-01-11 MEDIUM 6.5 CVE-2017-13891 In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management. Iphone Os 11.2+ Fix from $1,6002019-01-11 HIGH 8.6 CVE-2018-15460 A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthentic… Asyncos 11.0.2-044_md / 11.1.2-023_md+ Fix from $1,9502019-01-10