Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2018-10799 A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by … Brave 0.14.0+ Fix from $1,6002018-05-08 HIGH 7.8 CVE-2018-10776 The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and a… Mp3gain after 1.5.2 Fix from $1,9502018-05-07 MEDIUM 6.5 CVE-2018-0494EPSS 17% GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. Ubuntu Linux 1.19.5+ Fix from $1,6002018-05-06 HIGH 7.5 CVE-2018-9154 There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of servi… Jasper No fix yet Fix from $1,9502018-05-04 MEDIUM 5.9 CVE-2011-0704 389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modif… 389 Directory Server Mitigation only Fix from $1,6002018-05-04 HIGH 8.8 CVE-2017-15043 A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and… Gx440 Firmware 4.4.5 / 4.9+ Fix from $1,9502018-05-04 CRITICAL 9.8 CVE-2018-8869 In Lantech IDS 2102 2.0 and prior, nearly all input fields allow for arbitrary input on the device. A CVSS v3 base score of 9.8 has been calculated; … Ids 2102 Firmware Mitigation only Fix from $2,3002018-05-04 HIGH 8.8 CVE-2018-0287 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker… Webex Meetings Online Mitigation only Fix from $1,9502018-05-02 HIGH 8.6 CVE-2018-0234 A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access P… Aironet Access Point Software Mitigation only Fix from $1,9502018-05-02 HIGH 7.4 CVE-2018-0235 A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent atta… Wireless Lan Controller Software Mitigation only Fix from $1,9502018-05-02 CRITICAL 9.8 CVE-2018-0253EPSS 7% A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute ar… Secure Access Control System 5.8+ Fix from $2,3002018-05-02 CRITICAL 9.6 CVE-2018-0264 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker… Webex Business Suite 31 3.0+ Fix from $2,3002018-05-02 CRITICAL 9.8 CVE-2018-10578 An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.… Ap200 Firmware 1.2.9.15 / 2.0.0.10+ Fix from $2,3002018-05-02 HIGH 8.8 CVE-2018-1104 Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar… Ansible Tower after 3.2.3 Fix from $1,9502018-05-02 HIGH 8.6 CVE-2018-8115EPSS 35% A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while impo… Windows Host Compute Service Shim 0.6.10+ Fix from $1,9502018-05-02 HIGH 7.5 CVE-2018-10657 Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, relate… Synapse 0.28.1+ Fix from $1,9502018-05-02 HIGH 7.5 CVE-2018-5514 On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data plane exposure for virtual serve… Big Ip Local Traffic Manager after 13.1.0.5 Fix from $1,9502018-05-02 HIGH 7.5 CVE-2018-5517 On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The co… Big Ip Local Traffic Manager after 13.1.0.5 Fix from $1,9502018-05-02 HIGH 8.8 CVE-2018-10260EPSS 6% A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. Hrsale No fix yet Fix from $1,9502018-05-01 HIGH 7.5 CVE-2018-6589 CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vecto… Spectrum 10.01.02.ptf_10.1.239 / 10.2.3+ Fix from $1,9502018-05-01 HIGH 8.8 CVE-2018-1102 A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr… Openshift Patch available Fix from $1,9502018-04-30 MEDIUM 6.5 CVE-2017-17318 Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937… E5771h 937 Firmware Mitigation only Fix from $1,6002018-04-30 MEDIUM 6.1 CVE-2017-18262 Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shi… Blackboard Learn after 9.1 Fix from $1,6002018-04-30 HIGH 7.5 CVE-2018-10468 The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal ass… Useless Ethereum Token No fix yet Fix from $1,9502018-04-28 HIGH 7.5 CVE-2018-4832 A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS 7 V8.1 (All versions < V8.1 … Openpcs 7 7.2 / 13+ Fix from $1,9502018-04-24 HIGH 8.1 CVE-2016-9587EPSS 18% Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacke… Ansible 2.1.4 / 2.2.1+ Fix from $1,9502018-04-24 HIGH 7.5 CVE-2017-17258 Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C2… Ar120 S Firmware Mitigation only Fix from $1,9502018-04-24 HIGH 8.8 CVE-2014-0900 The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restriction… Android after 4.4.1 Fix from $1,9502018-04-20 CRITICAL 9.8 CVE-2018-8826 ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N… Rt Ac51u Firmware Mitigation only Fix from $2,3002018-04-20 MEDIUM 5.8 CVE-2018-0256 A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an unauthenticated, remote atta… Asr 5000 Series Software Mitigation only Fix from $1,6002018-04-19