Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2015-9239 ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. Ansi2html No fix yet Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10520 jadedown is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. Jadedown after 0.0.3 Fix from $1,9502018-05-31 HIGH 7.5 CVE-2016-10521 jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator. Jshamcrest after 0.7.1 Fix from $1,9502018-05-31 HIGH 8.8 CVE-2018-11481 TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data be… Ipc Tl Ipc223\(p\) 6 Firmware 1.0.21+ Fix from $1,9502018-05-30 MEDIUM 5.3 CVE-2018-10995 SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields). Debian Linux after 17.02.10.1 Fix from $1,6002018-05-30 HIGH 8.1 CVE-2018-11518 A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio sign… Legacy Ivr Firmware Mitigation only Fix from $1,9502018-05-30 HIGH 7.5 CVE-2018-11548 An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP ad… Eos Mitigation only Fix from $1,9502018-05-29 CRITICAL 9.8 CVE-2015-9235EPSS 9% In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (… Jsonwebtoken 4.2.2+ Fix from $2,3002018-05-29 HIGH 7.5 CVE-2015-9241 Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a … Hapi 11.1.3+ Fix from $1,9502018-05-29 HIGH 7.5 CVE-2015-9242 Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads … Ecstatic 1.4.0+ Fix from $1,9502018-05-29 HIGH 7.8 CVE-2018-11479EPSS 10% The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishe… Windscribe No fix yet Fix from $1,9502018-05-25 HIGH 8.1 CVE-2018-1137 An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who a… Moodle after 3.4.2 Fix from $1,9502018-05-25 MEDIUM 5.3 CVE-2017-17315 Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00… Dp300 Firmware Mitigation only Fix from $1,6002018-05-24 CRITICAL 9.8 CVE-2018-5487 NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) servic… Oncommand Unified Manager after 7.3 Fix from $2,3002018-05-24 MEDIUM 5.5 CVE-2018-1000040 In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service … Debian Linux after 1.12.0 Fix from $1,6002018-05-24 MEDIUM 5.5 CVE-2018-1000037 In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) vi… Debian Linux after 1.12.0 Fix from $1,6002018-05-24 HIGH 7.5 CVE-2018-11411 The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attackers to steal assets (e.g., tr… Dimoncoin Mitigation only Fix from $1,9502018-05-24 HIGH 8.8 CVE-2018-8176EPSS 23% A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsof… Office For Mac Patch available Fix from $1,9502018-05-23 HIGH 7.5 CVE-2018-11354 In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to… Wireshark Mitigation only Fix from $1,9502018-05-22 HIGH 7.5 CVE-2018-11357 In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in… Wireshark after 2.4.6 Fix from $1,9502018-05-22 HIGH 7.8 CVE-2017-2617 hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file… Hawtio 1.5.5+ Fix from $1,9502018-05-22 MEDIUM 6.5 CVE-2018-11321 An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulat… Joomla\! 3.8.8+ Fix from $1,6002018-05-22 HIGH 7.5 CVE-2018-11367 An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module. Cppcms 1.2.1+ Fix from $1,9502018-05-22 MEDIUM 6.5 CVE-2018-11315 The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can resul… Ct50 Firmware after 1.04.84 Fix from $1,6002018-05-20 HIGH 8.8 CVE-2018-4943EPSS 7% Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Successful exploitation could l… Push Notifications after 1.8.0 Fix from $1,9502018-05-19 HIGH 7.8 CVE-2018-4992 Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vulnerability. Successful explo… Creative Cloud after 4.4.1.298 Fix from $1,9502018-05-19 HIGH 7.5 CVE-2018-8867 In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP … Pacsystems Rx3i Cpe305 Firmware after 9.30 Fix from $1,9502018-05-18 MEDIUM 5.5 CVE-2018-11232 The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial o… Linux Kernel 4.10.2+ Fix from $1,6002018-05-18 HIGH 8.8 CVE-2018-9970 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ… Foxit Reader after 9.0.1.1049 Fix from $1,9502018-05-17 HIGH 8.8 CVE-2018-9935 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is req… Phantompdf after 9.0.1.1049 Fix from $1,9502018-05-17