Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2018-12065 A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (exe… Witycms No fix yet Fix from $2,3002018-06-08 HIGH 7.5 CVE-2018-12041 An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny service by sending specially con… Awus036nh Firmware Mitigation only Fix from $1,9502018-06-08 HIGH 7.5 CVE-2018-12046 DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and… Dedecms 5.7+ Fix from $1,9502018-06-08 HIGH 7.8 CVE-2018-0338 A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att… Unified Computing System Mitigation only Fix from $1,9502018-06-07 MEDIUM 6.1 CVE-2018-0355 A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross… Unified Communications Manager Mitigation only Fix from $1,6002018-06-07 HIGH 8.8 CVE-2018-0274 A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary she… Network Services Orchestrator after 4.4.2.0 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2018-0296 KEVEPSS 100% A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affec… Adaptive Security Appliance Software 6.1.0 / 6.2.2.3+ Fix from $1,9502018-06-07 HIGH 8.8 CVE-2018-3719 mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modi… Mixin Deep 1.3.1+ Fix from $1,9502018-06-07 HIGH 8.8 CVE-2018-3723 defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to m… Defaults Deep 0.2.4+ Fix from $1,9502018-06-07 CRITICAL 9.8 CVE-2017-16226 The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the gl… Static Eval 2.0.0+ Fix from $2,3002018-06-07 HIGH 7.5 CVE-2017-16113 The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed. Parsejson after 0.0.3 Fix from $1,9502018-06-07 HIGH 7.5 CVE-2018-3852 An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet ca… Ocularis No fix yet Fix from $1,9502018-06-06 MEDIUM 6.8 CVE-2018-1268 Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d… Loggregator 89.5 / 96.1+ Fix from $1,6002018-06-06 CRITICAL 9.1 CVE-2018-11808EPSS 6% Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to del… Manageengine Applications Manager Mitigation only Fix from $2,3002018-06-06 MEDIUM 5.3 CVE-2017-7653 The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that… Debian Linux after 1.4.15 Fix from $1,6002018-06-05 CRITICAL 9.8 CVE-2018-11678 plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie. Monstra Cms No fix yet Fix from $2,3002018-06-05 MEDIUM 5.9 CVE-2016-9042 An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticate… FreeBSD No fix yet Fix from $1,6002018-06-04 HIGH 7.5 CVE-2017-16023 Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to e… Decamelize Mitigation only Fix from $1,9502018-06-04 MEDIUM 5.9 CVE-2017-16026 Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero mem… Request 2.47.0+ Fix from $1,6002018-06-04 HIGH 7.5 CVE-2017-16005 Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, … Http Signature after 0.9.11 Fix from $1,9502018-06-04 HIGH 7.5 CVE-2017-16013 hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception… Hapi after 16.1.0 Fix from $1,9502018-06-04 MEDIUM 5.5 CVE-2018-1002100 In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the c… Kubernetes after 1.9.5 Fix from $1,6002018-06-02 HIGH 7.5 CVE-2018-5513 On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leadi… Big Ip Application Acceleration Manager after 13.1.0.4 Fix from $1,9502018-06-01 MEDIUM 5.9 CVE-2018-5522 On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute… Big Ip Application Acceleration Manager after 12.1.2 Fix from $1,6002018-06-01 MEDIUM 6.5 CVE-2016-10555 Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the ser… Jwt Simple after 0.3.0 Fix from $1,6002018-05-31 HIGH 7.5 CVE-2016-10539 negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Lan… Negotiator after 0.6.0 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10540 Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(… Minimatch after 3.0.1 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10542EPSS 8% ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending… Ws after 1.1.0 Fix from $1,9502018-05-31 MEDIUM 5.3 CVE-2016-10543 call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty par… Call after 3.0.1 Fix from $1,6002018-05-31 MEDIUM 5.9 CVE-2016-10544 uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibil… Uws after 0.10.8 Fix from $1,6002018-05-31