Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2018-8612 A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connec… Windows 10 Patch available Fix from $1,6002018-12-12 MEDIUM 5.7 CVE-2018-18358 Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy re… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 HIGH 8.8 CVE-2018-18347 Incorrect handling of failed navigations with invalid URLs in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to trick a … Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 MEDIUM 6.5 CVE-2018-18351 Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote atta… Chrome 71.0.3578.80+ Fix from $1,6002018-12-11 HIGH 8.8 CVE-2018-18354 Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launc… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 MEDIUM 5.5 CVE-2018-1652 IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9,… Datapower Gateway after 9.0.5 Fix from $1,6002018-12-11 HIGH 7.5 CVE-2018-20051 Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) v… Jooan Ja Q1h Wi Fi Camera Firmware No fix yet Fix from $1,9502018-12-10 MEDIUM 6.5 CVE-2018-20001 In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that … Libav No fix yet Fix from $1,6002018-12-10 HIGH 7.5 CVE-2018-19980 Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system… Nebula Capsule Projector Firmware No fix yet Fix from $1,9502018-12-08 MEDIUM 6.5 CVE-2018-19967 An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen … Debian Linux after 4.11.1 Fix from $1,6002018-12-08 HIGH 7.0 CVE-2018-19960 The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging,… Onionshare after 1.3.1 Fix from $1,9502018-12-07 HIGH 8.1 CVE-2018-16528 Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in pr… Amazon Web Services Freertos after 1.3.1 Fix from $1,9502018-12-06 HIGH 7.8 CVE-2018-9547 In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privileg… Android Patch available Fix from $1,9502018-12-06 MEDIUM 6.1 CVE-2018-1504 IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a… I2 Enterprise Insight Analysis Mitigation only Fix from $1,6002018-12-06 CRITICAL 9.8 CVE-2018-19864EPSS 25% NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov… Nvrmini2 Firmware after 3.9.1 Fix from $2,3002018-12-05 HIGH 8.8 CVE-2018-6088 An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox v… Chrome 66.0.3359.117+ Fix from $1,9502018-12-04 MEDIUM 6.5 CVE-2018-6089 A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a r… Chrome 66.0.3359.117+ Fix from $1,6002018-12-04 HIGH 7.5 CVE-2018-6101 A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML … Linux Desktop 66.0.3359.117+ Fix from $1,9502018-12-04 MEDIUM 6.5 CVE-2018-6115 Inappropriate setting of the SEE_MASK_FLAG_NO_UI flag in file downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentia… Chrome 66.0.3359.117+ Fix from $1,6002018-12-04 HIGH 7.5 CVE-2018-19591EPSS 6% In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socke… Fedora after 2.28 Fix from $1,9502018-12-04 HIGH 8.8 CVE-2018-19788EPSS 11% A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command. Debian Linux Patch available Fix from $1,9502018-12-03 MEDIUM 6.5 CVE-2018-19791 The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the res… Openlitespeed 1.5.0+ Fix from $1,6002018-12-03 CRITICAL 9.8 CVE-2018-15715 Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable… Zoom 4.1.34801.1116 / 4.1.34814.1119+ Fix from $2,3002018-11-30 HIGH 7.5 CVE-2018-3948EPSS 23% An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL… Tl R600vpn Firmware No fix yet Fix from $1,9502018-11-30 MEDIUM 6.5 CVE-2018-9072 In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file… Xclarity Integrator 5.5+ Fix from $1,6002018-11-30 MEDIUM 5.5 CVE-2018-19755 There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (o… Netwide Assembler No fix yet Fix from $1,6002018-11-30 HIGH 7.5 CVE-2018-19654 An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a compone… Sales \& Company Management System after 2018-06-06 Fix from $1,9502018-11-29 HIGH 7.8 CVE-2017-18317 Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon… Msm8996au Firmware Mitigation only Fix from $1,9502018-11-28 CRITICAL 9.8 CVE-2017-18318 Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12, SD 425, SD 430, SD 450, SD … Msm8996au Firmware Mitigation only Fix from $2,3002018-11-28 MEDIUM 5.3 CVE-2018-13361EPSS 17% User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter. Terramaster Operating System No fix yet Fix from $1,6002018-11-27