Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2018-1000656 The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount o… Flask 0.12.3+ Fix from $1,9502018-08-20 HIGH 7.1 CVE-2018-1000647 LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial… Librehealth Ehr No fix yet Fix from $1,9502018-08-20 HIGH 8.8 CVE-2018-15358 An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version… Esp 200 Firmware Mitigation only Fix from $1,9502018-08-17 HIGH 8.8 CVE-2018-10873 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check… Debian Linux Patch available Fix from $1,9502018-08-17 HIGH 7.8 CVE-2018-15122 An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by deco… Justassembly Mitigation only Fix from $1,9502018-08-16 HIGH 8.6 CVE-2018-0418 A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow a… Ios Xr after 6.3.3_base Fix from $1,9502018-08-15 HIGH 7.5 CVE-2018-0419 A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker t… Email Security Appliance Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2018-0409 A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Vi… Telepresence Video Communication Server Mitigation only Fix from $1,9502018-08-15 HIGH 7.8 CVE-2018-8412 An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing … Office For Mac Patch available Fix from $1,9502018-08-15 HIGH 8.8 CVE-2018-8414 KEVEPSS 74% A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution V… Windows 10 1703 Patch available Fix from $1,9502018-08-15 HIGH 7.0 CVE-2018-8339 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an ins… Windows 10 Mitigation only Fix from $1,9502018-08-15 MEDIUM 5.3 CVE-2018-12537 In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed ch… Vert.x after 3.5.1 Fix from $1,6002018-08-14 MEDIUM 5.3 CVE-2018-3776 Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. Nextcloud Server 11.0.5 / 12.0.3+ Fix from $1,6002018-08-12 MEDIUM 6.5 CVE-2018-15185 PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PH… Naukri Clone Script No fix yet Fix from $1,6002018-08-10 MEDIUM 6.3 CVE-2018-10908 It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image… Virtualization 4.20.37+ Fix from $1,6002018-08-09 MEDIUM 6.5 CVE-2017-16790 An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request… Symfony after 3.3.12 Fix from $1,6002018-08-06 HIGH 7.5 CVE-2018-13877 The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smar… Megacryptopolis Mitigation only Fix from $1,9502018-08-06 HIGH 8.8 CVE-2018-7059 Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permissi… Aruba Clearpass Policy Manager 6.6.9+ Fix from $1,9502018-08-06 HIGH 7.8 CVE-2018-14923 A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback. Ezplayer Mitigation only Fix from $1,9502018-08-03 CRITICAL 9.8 CVE-2018-3777 Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API requests. Restforce 3.0.0+ Fix from $2,3002018-08-03 CRITICAL 9.8 CVE-2018-9866 A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance… Global Management System after 8.1 Fix from $2,3002018-08-03 HIGH 7.2 CVE-2018-14774 An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 throug… Symfony after 4.1.2 Fix from $1,9502018-08-03 HIGH 7.5 CVE-2018-14872 An issue was discovered in Rincewind 0.1. A reinstall vulnerability exists because the parameter p of index.php and another file named commonPages.ph… Rincewind No fix yet Fix from $1,9502018-08-03 HIGH 7.5 CVE-2018-10921 Certain input files may trigger an integer overflow in ttembed input file processing. This overflow could potentially lead to corruption of the input… Ttembed No fix yet Fix from $1,9502018-08-02 MEDIUM 5.5 CVE-2018-10922 An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of service condition due to ttembe… Ttembed No fix yet Fix from $1,6002018-08-02 MEDIUM 6.8 CVE-2018-10920 Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache. Knot Resolver 2.4.1+ Fix from $1,6002018-08-02 MEDIUM 5.3 CVE-2018-12448 Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, … Whale 1.3.48.4+ Fix from $1,6002018-08-02 HIGH 7.5 CVE-2016-9579 A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re… Ceph Storage Patch available Fix from $1,9502018-08-01 HIGH 7.8 CVE-2018-3650 Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypas… Distribution For Python 2018+ Fix from $1,9502018-08-01 MEDIUM 6.5 CVE-2018-10916 It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on th… Ubuntu Linux after 4.8.3 Fix from $1,6002018-08-01