Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2017-1002157 modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution. Modulemd after 1.3.1 Fix from $2,3002019-01-10 HIGH 7.5 CVE-2018-20684 In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwritin… Winscp after 5.13.7 Fix from $1,9502019-01-10 HIGH 8.6 CVE-2018-15453 A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of … Email Security Appliance Firmware Mitigation only Fix from $1,9502019-01-10 MEDIUM 5.5 CVE-2018-4032 An exploitable privilege escalation vulnerability exists in the way the CleanMyMac X software improperly validates inputs. An attacker with local acc… Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4033 The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4034 The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with l… Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4035 The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with l… Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4036 The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4037 The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4041 An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4042 An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4043 An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user… Cleanmymac X No fix yet Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4044 An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4045 An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An … Cleanmymac X No fix yet Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4046 An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. A user… Cleanmymac X Mitigation only Fix from $1,6002019-01-10 MEDIUM 5.5 CVE-2018-4047 An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An … Cleanmymac X Mitigation only Fix from $1,6002019-01-10 HIGH 8.1 CVE-2018-20683 commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" im… Gitolite 3.6.11+ Fix from $1,9502019-01-10 HIGH 7.8 CVE-2018-16185 RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Contr… D2200 Firmware after 3.1.10137.0 Fix from $1,9502019-01-09 HIGH 7.5 CVE-2018-16196 Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 -… Centum Cs 3000 Firmware Mitigation only Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-6160 JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) … Chrome 68.0.3440.75+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-6169 Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of… Chrome 68.0.3440.75+ Fix from $1,6002019-01-09 HIGH 8.8 CVE-2018-6139 Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to … Chrome 67.0.3396.62+ Fix from $1,9502019-01-09 HIGH 8.8 CVE-2018-6140 Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a use… Chrome 67.0.3396.62+ Fix from $1,9502019-01-09 MEDIUM 5.4 CVE-2018-6110 Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a loc… Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 HIGH 8.8 CVE-2018-6111 An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary… Chrome 66.0.3359.117+ Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-6113 Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform dom… Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-6114 Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security … Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-6096 A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker… Chrome 66.0.3359.117+ Fix from $1,6002019-01-09 HIGH 8.8 CVE-2018-20065 Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without … Chrome 71.0.3578.80+ Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-20070 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents o… Chrome 71.0.3578.80+ Fix from $1,6002019-01-09