Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Kernel HIGH 7.8
CVE-2019-13272 KEVEPSS 52%

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptr…

Fix: 3.16.71 / 4.2+
Fix from $1,950 2019-07-17
Netscaler Sd Wan HIGH 8.8
CVE-2019-12991 KEVEPSS 74%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $1,950 2019-07-16
Netscaler Sd Wan CRITICAL 9.8
CVE-2019-12989 KEVEPSS 94%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

Fix: 10.0.8 / 10.2.3+
Fix from $2,300 2019-07-16
Windows 7 HIGH 7.8
CVE-2019-1132 KEVEPSS 10%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…

Patch available
Fix from $1,950 2019-07-15
Windows 10 1507 HIGH 7.8
CVE-2019-1130 KEV

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…

Patch available
Fix from $1,950 2019-07-15
Windows 10 1703 HIGH 7.8
CVE-2019-1129 KEV

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…

Patch available
Fix from $1,950 2019-07-15
Windows 10 1507 HIGH 7.8
CVE-2019-0880 KEV

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnera…

Patch available
Fix from $1,950 2019-07-15
Dotnetnuke HIGH 7.5
CVE-2018-18325 KEVEPSS 74%

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete…

Fix: after 9.2.2
Fix from $1,950 2019-07-03
Dotnetnuke HIGH 7.5
CVE-2018-15811 KEVEPSS 74%

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

Fix: after 9.2.1
Fix from $1,950 2019-07-03
Linear Emerge Essential Firmware CRITICAL 9.8
CVE-2019-7256 KEVEPSS 97%

Linear eMerge E3-Series devices allow Command Injections.

Fix: after 1.00-06
Fix from $2,300 2019-07-02
Chrome MEDIUM 6.5
CVE-2019-5786 KEVEPSS 62%

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access v…

Fix: 72.0.3626.121+
Fix from $1,600 2019-06-27
Windows 10 1507 HIGH 7.8
CVE-2019-1069 KEVEPSS 6%

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully …

Patch available
Fix from $1,950 2019-06-12
Windows 10 1607 HIGH 7.8
CVE-2019-1064 KEVEPSS 7%

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successf…

Patch available
Fix from $1,950 2019-06-12
Airos CRITICAL 9.8
CVE-2010-5330 KEVEPSS 35%

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitize…

Fix: 4.0.1 / 5.3.5+
Fix from $2,300 2019-06-11
Ubuntu Linux CRITICAL 9.8
CVE-2019-10149 KEVEPSS 100%

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c …

Fix: after 4.91
Fix from $2,300 2019-06-05
Fortiproxy HIGH 7.5
CVE-2018-13382 KEVEPSS 82%

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, …

Fix: 1.2.9 / 5.4.11+
Fix from $1,950 2019-06-04
Fortiproxy CRITICAL 9.8
CVE-2018-13379 KEVEPSS 100%

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4…

Fix: 1.2.9 / 5.4.13+
Fix from $2,300 2019-06-04
Crowd CRITICAL 9.8
CVE-2019-11580 KEVEPSS 95%

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentic…

Fix: 3.0.5 / 3.1.6+
Fix from $2,300 2019-06-03
Cms HIGH 8.8
CVE-2019-9875 KEVEPSS 14%

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi…

Fix: after 9.1
Fix from $1,950 2019-05-31
Cms CRITICAL 9.8
CVE-2019-9874 KEVEPSS 84%

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo…

Fix: after 8.2
Fix from $2,300 2019-05-31
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2019-9670 KEVEPSS 100%

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr…

Fix: 8.7.11+
Fix from $2,300 2019-05-29
Fortiproxy MEDIUM 6.5
CVE-2018-13383 KEVEPSS 34%

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, …

Fix: 1.2.9 / 5.2.15+
Fix from $1,600 2019-05-29
U.motion Builder CRITICAL 9.8
CVE-2018-7841 KEVEPSS 73%

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper s…

Mitigation only
Fix from $2,300 2019-05-22
Receiver CRITICAL 9.8
CVE-2019-11634 KEVEPSS 8%

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Fix: 1904+
Fix from $2,300 2019-05-22
Windows 10 1507 HIGH 8.8
CVE-2019-0903 KEVEPSS 22%

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Rem…

Patch available
Fix from $1,950 2019-05-16
Windows 10 1507 HIGH 7.8
CVE-2019-0863 KEVEPSS 5%

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Priv…

Patch available
Fix from $1,950 2019-05-16
Windows 7 CRITICAL 9.8
CVE-2019-0708 KEVEPSS 100%

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects…

Patch available
Fix from $2,300 2019-05-16
N1a1 Firmware CRITICAL 9.8
CVE-2018-14839 KEVEPSS 89%

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p…

Mitigation only
Fix from $2,300 2019-05-14
Whatsapp CRITICAL 9.8
CVE-2019-3568 KEVEPSS 39%

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target ph…

Fix: 2.18.15 / 2.18.348+
Fix from $2,300 2019-05-14
Connect Secure CRITICAL 10.0
CVE-2019-11510 KEVEPSS 100%

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can se…

Patch available
Fix from $2,300 2019-05-08