Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Antivirus HIGH 7.8
CVE-2018-5086

In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other i…

No fix yet
Fix from $1,950 2018-01-03
Antivirus HIGH 7.8
CVE-2018-5087

In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other i…

No fix yet
Fix from $1,950 2018-01-03
Antivirus HIGH 7.8
CVE-2018-5088

In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other i…

No fix yet
Fix from $1,950 2018-01-03
Cobbler CRITICAL 9.8
CVE-2017-1000469EPSS 5%

Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as r…

Fix: after 2.8.2
Fix from $2,300 2018-01-03
B2evolution CRITICAL 9.8
CVE-2017-1000423

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in …

Fix: after 6.8.10
Fix from $2,300 2018-01-02
Fedora HIGH 7.5
CVE-2014-8119

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augea…

Fix: after 0.2.6
Fix from $1,950 2017-12-29
Wps Office MEDIUM 5.5
CVE-2017-17967

pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.

Mitigation only
Fix from $1,600 2017-12-28
Php Multivendor Ecommerce HIGH 8.6
CVE-2017-17952

PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid …

No fix yet
Fix from $1,950 2017-12-28
Sysgauge HIGH 7.5
CVE-2017-15667

In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent…

No fix yet
Fix from $1,950 2017-12-28
Pdf Xchange Viewer HIGH 7.8
CVE-2017-13056EPSS 7%

The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.

No fix yet
Fix from $1,950 2017-12-27
Iphone Os MEDIUM 6.6
CVE-2017-7154

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The i…

Fix: 10.13.2 / 11.2+
Fix from $1,600 2017-12-27
Asterisk HIGH 7.5
CVE-2017-17850EPSS 66%

An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages cr…

Fix: after 15.1.4
Fix from $1,950 2017-12-27
Linux Kernel MEDIUM 5.5
CVE-2017-17862

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This beh…

Fix: after 4.14.8
Fix from $1,600 2017-12-27
Debian Linux HIGH 7.5
CVE-2017-17846

An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily…

Fix: 1.9.9+
Fix from $1,950 2017-12-27
Mac Os X HIGH 7.8
CVE-2017-13858

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to…

Fix: 10.13.2+
Fix from $1,950 2017-12-25
Mac Os X HIGH 7.8
CVE-2017-13848

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to…

Fix: 10.13.2+
Fix from $1,950 2017-12-25
Factorytalk Alarms And Events HIGH 7.5
CVE-2017-14022

An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated …

Fix: after 2.90
Fix from $1,950 2017-12-23
Ireader MEDIUM 6.5
CVE-2017-15310

Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vu…

Fix: 8.0.2.301+
Fix from $1,600 2017-12-22
Baggio L03a Firmware MEDIUM 6.5
CVE-2017-15322

Some Huawei smartphones with software of BGO-L03C158B003CUSTC158D001 and BGO-L03C331B009CUSTC331D001 have a DoS vulnerability due to insufficient inp…

Mitigation only
Fix from $1,600 2017-12-22
S5700 Firmware HIGH 7.5
CVE-2017-15324

Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) pac…

Mitigation only
Fix from $1,950 2017-12-22
Ireader HIGH 8.8
CVE-2017-15308

Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An…

Fix: 8.0.2.301+
Fix from $1,950 2017-12-22
H2o HIGH 7.5
CVE-2017-10868

H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.

Fix: 2.2.3+
Fix from $1,950 2017-12-22
H2o HIGH 7.5
CVE-2017-10908

H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.

Fix: after 2.2.3
Fix from $1,950 2017-12-22
Big Ip Access Policy Manager HIGH 7.5
CVE-2017-6129

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, in some circumstances, APM tunneled VPN flows can cause a VPN/PPP connflow to be prematurely fre…

Mitigation only
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6132

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6…

Fix: after 12.1.2
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6133

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, undisclosed HTTP …

Fix: after 12.1.2
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager MEDIUM 6.5
CVE-2017-6134

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.…

Fix: after 12.1.2
Fix from $1,600 2017-12-21
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2017-6136

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.0.0 - 12.1.2, undisclosed …

Fix: after 12.1.2
Fix from $1,600 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6138

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, malicious re…

Fix: after 12.1.2
Fix from $1,950 2017-12-21
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6140

On the BIG-IP 2000s, 2200s, 4000s, 4200v, i5600, i5800, i7600, i7800, i10600,i10800, and VIPRION 4450 blades, running version 11.5.0, 11.5.1, 11.5.2,…

Mitigation only
Fix from $1,950 2017-12-21