Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2018-8038EPSS 11% Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response… Cxf Fediz 1.4.4+ Fix from $1,9502018-07-05 CRITICAL 9.8 CVE-2018-3749 The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can co… Deap 1.0.1+ Fix from $2,3002018-07-03 CRITICAL 9.8 CVE-2018-3750 The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacke… Deep Extend after 0.5.0 Fix from $2,3002018-07-03 CRITICAL 9.8 CVE-2018-3751 The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the att… Merge Recursive after 0.3.0 Fix from $2,3002018-07-03 CRITICAL 9.8 CVE-2018-3752 The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attac… Merge Options after 1.0.0 Fix from $2,3002018-07-03 CRITICAL 9.8 CVE-2018-3753 The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attac… Merge Object after 1.0.0 Fix from $2,3002018-07-03 MEDIUM 5.5 CVE-2018-9242 The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to d… Pan Os after 8.0.9 Fix from $1,6002018-07-03 CRITICAL 9.6 CVE-2018-11314 The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and… Roku Firmware Mitigation only Fix from $2,3002018-07-03 CRITICAL 9.6 CVE-2018-11316 The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device contro… Sonos Firmware Mitigation only Fix from $2,3002018-07-03 MEDIUM 5.3 CVE-2018-7635 Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, whi… Whale 1.0.41.8+ Fix from $1,6002018-07-03 HIGH 8.8 CVE-2018-7777EPSS 32% The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwa… U.motion Builder 1.3.4+ Fix from $1,9502018-07-03 CRITICAL 9.8 CVE-2018-7784 In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated… U.motion 1.3.4+ Fix from $2,3002018-07-03 MEDIUM 5.3 CVE-2018-7787 In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parame… U.motion Builder 1.3.4+ Fix from $1,6002018-07-03 HIGH 8.2 CVE-2018-4851 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device c… Siclock Tc400 Firmware Mitigation only Fix from $1,9502018-07-03 HIGH 8.8 CVE-2018-10843 source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile… Openshift Container Platform 3.7.53+ Fix from $1,9502018-07-02 HIGH 7.5 CVE-2018-13056 An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_… Zzcms No fix yet Fix from $1,9502018-07-02 MEDIUM 6.5 CVE-2017-17175 Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) … Mate 9 Pro Mitigation only Fix from $1,6002018-07-02 HIGH 7.8 CVE-2018-10874 In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con… Ansible Engine Mitigation only Fix from $1,9502018-07-02 HIGH 7.5 CVE-2018-12999EPSS 9% Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web se… Manageengine Desktop Central No fix yet Fix from $1,9502018-06-29 HIGH 7.5 CVE-2018-12988 GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI. Greencms No fix yet Fix from $1,9502018-06-29 MEDIUM 5.3 CVE-2018-5528 Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7. Big Ip Access Policy Manager after 13.1.0.7 Fix from $1,6002018-06-27 HIGH 7.5 CVE-2018-3840 A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a netw… Renderman No fix yet Fix from $1,9502018-06-26 MEDIUM 6.5 CVE-2018-1374 An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connect… Websphere Mq Mitigation only Fix from $1,6002018-06-26 HIGH 8.8 CVE-2018-12712 An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" functi… Joomla\! after 3.8.8 Fix from $1,9502018-06-26 MEDIUM 6.5 CVE-2018-1000607 A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to c… Fortify Cloudscan after 1.5.1 Fix from $1,6002018-06-26 HIGH 8.1 CVE-2018-1000523 topydo contains a CWE-20: Improper Input Validation vulnerability in ListFormatParser::parse, file topydo/lib/ListFormat.py line 292 as of d4f843dac7… Topydo Mitigation only Fix from $1,9502018-06-26 HIGH 7.5 CVE-2018-1000531 inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can re… Prime Jwt after 1.3.0 Fix from $1,9502018-06-26 CRITICAL 9.8 CVE-2018-1000533EPSS 73% klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that ca… Gitlist after 0.6.0 Fix from $2,3002018-06-26 MEDIUM 5.5 CVE-2018-1000205 U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This… U Boot after 2018.07 Fix from $1,6002018-06-26 HIGH 7.5 CVE-2017-9312 Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service… Allen Bradley L30erms Firmware after 30 Fix from $1,9502018-06-25