Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2018-11266 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper input validation can lead to an i… Android Patch available Fix from $1,9502018-11-27 CRITICAL 9.8 CVE-2018-13315 Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthent… A3002ru Firmware No fix yet Fix from $2,3002018-11-26 MEDIUM 5.9 CVE-2018-14663 An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of… Dnsdist after 1.3.2 Fix from $1,6002018-11-26 CRITICAL 9.8 CVE-2018-19530 HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when conf… Httl after 1.0.11 Fix from $2,3002018-11-26 CRITICAL 9.8 CVE-2018-19531 HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsa… Httl after 1.0.11 Fix from $2,3002018-11-26 HIGH 7.5 CVE-2018-12543EPSS 36% In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, … Mosquitto after 1.5.2 Fix from $1,9502018-11-15 MEDIUM 6.5 CVE-2018-9347 In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary … Android Patch available Fix from $1,6002018-11-14 HIGH 7.8 CVE-2018-9523 In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This c… Android Patch available Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-6074 Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a cra… Chrome 65.0.3325.146+ Fix from $1,9502018-11-14 CRITICAL 9.6 CVE-2018-17472 Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <if… Chrome 70.0.3538.67+ Fix from $2,3002018-11-14 HIGH 8.8 CVE-2018-19204 PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS command… Prtg Network Monitor 18.3.44.2054+ Fix from $1,9502018-11-12 MEDIUM 5.9 CVE-2018-14644 An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can… Recursor after 4.1.4 Fix from $1,6002018-11-09 MEDIUM 6.5 CVE-2018-15450 A vulnerability in the web-based UI of Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to overwrite files on the fi… Prime Collaboration Mitigation only Fix from $1,6002018-11-08 MEDIUM 6.5 CVE-2018-15449 A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenticated, remote attacker to cau… Video Surveillance Media Server Mitigation only Fix from $1,6002018-11-08 HIGH 8.8 CVE-2018-19114 An issue was discovered in MinDoc through v1.0.2. It allows attackers to gain privileges by uploading an image file with contents that represent an a… Mindoc after 1.0.2 Fix from $1,9502018-11-08 MEDIUM 5.5 CVE-2018-6433 A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to … Fabric Operating System 7.4.2d / 8.0.2f+ Fix from $1,6002018-11-08 HIGH 7.5 CVE-2018-16472 A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe… Debian Linux after 1.0.1 Fix from $1,9502018-11-06 HIGH 7.5 CVE-2018-9362 In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to improper input validation. This could lead to re… Android Patch available Fix from $1,9502018-11-06 HIGH 7.5 CVE-2014-10077 Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash… I18n 0.8.0+ Fix from $1,9502018-11-06 HIGH 8.6 CVE-2018-15454 A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th… Adaptive Security Appliance Software 6.1.0.7 / 6.2.0.6+ Fix from $1,9502018-11-01 MEDIUM 6.5 CVE-2016-2125EPSS 9% It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh… Gluster Storage 4.3.13 / 4.4.8+ Fix from $1,6002018-10-31 MEDIUM 6.5 CVE-2018-14661 It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln… Debian Linux Mitigation only Fix from $1,6002018-10-31 HIGH 7.5 CVE-2018-15318 In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the… Big Ip Local Traffic Manager after 14.0.0.2 Fix from $1,9502018-10-31 HIGH 7.5 CVE-2018-15319 On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to … Big Ip Local Traffic Manager after 14.0.0.2 Fix from $1,9502018-10-31 MEDIUM 5.9 CVE-2018-15323 On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, in certain circumstances, when processing traffic through a Virtual Server with an associated MQTT prof… Big Ip Local Traffic Manager after 14.0.0.2 Fix from $1,6002018-10-31 MEDIUM 5.9 CVE-2018-15324 On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM portal access. Big Ip Access Policy Manager after 14.0.0.2 Fix from $1,6002018-10-31 HIGH 7.5 CVE-2018-16469 The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties… Merge 1.2.1+ Fix from $1,9502018-10-30 HIGH 7.5 CVE-2015-5159 python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request. Kdcproxy 0.3.2+ Fix from $1,9502018-10-30 HIGH 7.8 CVE-2018-10711 The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Rest… A Tuning 1.0.6.2 / 1.0.35.1+ Fix from $1,9502018-10-30 HIGH 7.8 CVE-2018-11872 Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SD… Sd 845 Firmware Mitigation only Fix from $1,9502018-10-29