Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2019-13272 KEVEPSS 52% In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptr… Linux Kernel 3.16.71 / 4.2+ Fix from $1,9502019-07-17 HIGH 8.8 CVE-2019-12991 KEVEPSS 74% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $1,9502019-07-16 CRITICAL 9.8 CVE-2019-12989 KEVEPSS 94% Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. Netscaler Sd Wan 10.0.8 / 10.2.3+ Fix from $2,3002019-07-16 HIGH 7.8 CVE-2019-1132 KEVEPSS 10% An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… Windows 7 Patch available Fix from $1,9502019-07-15 HIGH 7.8 CVE-2019-1130 KEV An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o… Windows 10 1507 Patch available Fix from $1,9502019-07-15 HIGH 7.8 CVE-2019-1129 KEV An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o… Windows 10 1703 Patch available Fix from $1,9502019-07-15 HIGH 7.8 CVE-2019-0880 KEV A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnera… Windows 10 1507 Patch available Fix from $1,9502019-07-15 HIGH 7.5 CVE-2018-18325 KEVEPSS 74% DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete… Dotnetnuke after 9.2.2 Fix from $1,9502019-07-03 HIGH 7.5 CVE-2018-15811 KEVEPSS 74% DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. Dotnetnuke after 9.2.1 Fix from $1,9502019-07-03 CRITICAL 9.8 CVE-2019-7256 KEVEPSS 97% Linear eMerge E3-Series devices allow Command Injections. Linear Emerge Essential Firmware after 1.00-06 Fix from $2,3002019-07-02 MEDIUM 6.5 CVE-2019-5786 KEVEPSS 62% Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access v… Chrome 72.0.3626.121+ Fix from $1,6002019-06-27 HIGH 7.8 CVE-2019-1069 KEVEPSS 6% An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully … Windows 10 1507 Patch available Fix from $1,9502019-06-12 HIGH 7.8 CVE-2019-1064 KEVEPSS 7% An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successf… Windows 10 1607 Patch available Fix from $1,9502019-06-12 CRITICAL 9.8 CVE-2010-5330 KEVEPSS 35% On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitize… Airos 4.0.1 / 5.3.5+ Fix from $2,3002019-06-11 CRITICAL 9.8 CVE-2019-10149 KEVEPSS 100% A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c … Ubuntu Linux after 4.91 Fix from $2,3002019-06-05 HIGH 7.5 CVE-2018-13382 KEVEPSS 82% An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, … Fortiproxy 1.2.9 / 5.4.11+ Fix from $1,9502019-06-04 CRITICAL 9.8 CVE-2018-13379 KEVEPSS 100% An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4… Fortiproxy 1.2.9 / 5.4.13+ Fix from $2,3002019-06-04 CRITICAL 9.8 CVE-2019-11580 KEVEPSS 95% Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentic… Crowd 3.0.5 / 3.1.6+ Fix from $2,3002019-06-03 HIGH 8.8 CVE-2019-9875 KEVEPSS 14% Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi… Cms after 9.1 Fix from $1,9502019-05-31 CRITICAL 9.8 CVE-2019-9874 KEVEPSS 84% Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo… Cms after 8.2 Fix from $2,3002019-05-31 CRITICAL 9.8 CVE-2019-9670 KEVEPSS 100% mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr… Zimbra Collaboration Suite 8.7.11+ Fix from $2,3002019-05-29 MEDIUM 6.5 CVE-2018-13383 KEVEPSS 34% A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, … Fortiproxy 1.2.9 / 5.2.15+ Fix from $1,6002019-05-29 CRITICAL 9.8 CVE-2018-7841 KEVEPSS 73% A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper s… U.motion Builder Mitigation only Fix from $2,3002019-05-22 CRITICAL 9.8 CVE-2019-11634 KEVEPSS 8% Citrix Workspace App before 1904 for Windows has Incorrect Access Control. Receiver 1904+ Fix from $2,3002019-05-22 HIGH 8.8 CVE-2019-0903 KEVEPSS 22% A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Rem… Windows 10 1507 Patch available Fix from $1,9502019-05-16 HIGH 7.8 CVE-2019-0863 KEVEPSS 5% An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Priv… Windows 10 1507 Patch available Fix from $1,9502019-05-16 CRITICAL 9.8 CVE-2019-0708 KEVEPSS 100% A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects… Windows 7 Patch available Fix from $2,3002019-05-16 CRITICAL 9.8 CVE-2018-14839 KEVEPSS 89% LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p… N1a1 Firmware Mitigation only Fix from $2,3002019-05-14 CRITICAL 9.8 CVE-2019-3568 KEVEPSS 39% A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target ph… Whatsapp 2.18.15 / 2.18.348+ Fix from $2,3002019-05-14 CRITICAL 10.0 CVE-2019-11510 KEVEPSS 100% In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can se… Connect Secure Patch available Fix from $2,3002019-05-08