Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2018-20404 ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which ca… Epia E900 Firmware No fix yet Fix from $1,9502018-12-26 HIGH 8.8 CVE-2018-7832 An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executa… Pro Face Gp Pro Ex after 4.08 Fix from $1,9502018-12-24 MEDIUM 5.9 CVE-2018-20424 Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp req… Discuzx No fix yet Fix from $1,6002018-12-24 MEDIUM 6.5 CVE-2018-1000883 Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. T… Plug 1.3.5+ Fix from $1,6002018-12-20 HIGH 7.8 CVE-2018-19005 Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be exploited by processing specially… Cscape 9.80.75.3+ Fix from $1,9502018-12-20 HIGH 7.5 CVE-2018-15330 On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a pay… Big Ip Local Traffic Manager after 14.0.0.2 Fix from $1,9502018-12-20 MEDIUM 6.5 CVE-2018-1000873 Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes … Active Iq Unified Manager 2.9.8 / 11.2.0.3.23+ Fix from $1,6002018-12-20 HIGH 8.8 CVE-2018-1000849 Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) … Alpine Linux 2.6.10 / 2.7.6+ Fix from $1,9502018-12-20 HIGH 8.8 CVE-2018-5199 In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to malicious file. A remote unauthe… Veraport G3 Mitigation only Fix from $1,9502018-12-20 MEDIUM 6.5 CVE-2018-20301 An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endp… Coherence 0.5.2+ Fix from $1,6002018-12-20 MEDIUM 6.5 CVE-2018-11799 Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that result… Oozie 5.1.0+ Fix from $1,6002018-12-19 HIGH 7.3 CVE-2018-18999 WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attack… Webaccess\/scada Mitigation only Fix from $1,9502018-12-19 HIGH 7.5 CVE-2018-17194 When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE … Nifi after 1.7.1 Fix from $1,9502018-12-19 MEDIUM 5.5 CVE-2018-19522 DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffer containing user defined con… Driveragent No fix yet Fix from $1,6002018-12-18 MEDIUM 6.5 CVE-2018-20189 In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is… Debian Linux Patch available Fix from $1,6002018-12-17 MEDIUM 6.5 CVE-2018-19936 PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion. Printeron No fix yet Fix from $1,6002018-12-17 HIGH 7.8 CVE-2018-19295 Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks. Singularity after 2.6.0 Fix from $1,9502018-12-17 MEDIUM 5.5 CVE-2018-20168 Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a den… Gvisor 2018-08-22+ Fix from $1,6002018-12-17 HIGH 7.2 CVE-2018-20159EPSS 10% i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with … I Doit No fix yet Fix from $1,9502018-12-15 HIGH 7.2 CVE-2018-20156 The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throug… Wp Maintenance Mode 2.0.7+ Fix from $1,9502018-12-14 MEDIUM 6.5 CVE-2018-20152 In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input. WordPress 4.9.9 / 5.0.1+ Fix from $1,6002018-12-14 MEDIUM 6.5 CVE-2018-1977 IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user c… Db2 Patch available Fix from $1,6002018-12-14 HIGH 8.1 CVE-2018-16873EPSS 66% In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the impo… Go 1.10.6 / 1.11.3+ Fix from $1,9502018-12-14 HIGH 8.1 CVE-2018-16874EPSS 5% In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malic… Go 1.10.6 / 1.11.3+ Fix from $1,9502018-12-14 HIGH 7.5 CVE-2018-16875EPSS 6% The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which m… Go 1.10.6 / 1.11.3+ Fix from $1,9502018-12-14 HIGH 8.8 CVE-2018-13814 A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All ver… Simatic Hmi Comfort Panels Firmware 14.0+ Fix from $1,9502018-12-13 HIGH 7.5 CVE-2018-16556 A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-40… Simatic S7 400 Firmware 8.2.1+ Fix from $1,9502018-12-13 HIGH 7.5 CVE-2018-20127 An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary files via a mixed-case extension… Zzzphp No fix yet Fix from $1,9502018-12-13 MEDIUM 6.1 CVE-2018-1478 IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuadi… Bigfix Platform after 9.5.9 Fix from $1,6002018-12-12 HIGH 8.8 CVE-2018-8635EPSS 6% An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request… Sharepoint Enterprise Server Patch available Fix from $1,9502018-12-12