Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ametys CRITICAL 9.8
CVE-2017-16935EPSS 6%

Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restr…

Fix: 4.0.3+
Fix from $2,300 2017-11-24
Vicky Al00a MEDIUM 5.5
CVE-2017-8175

The Bastet of some Huawei mobile phones with software earlier than Vicky-AL00AC00B167 versions, earlier than Victoria-AL00AC00B167 versions, earlier …

Mitigation only
Fix from $1,600 2017-11-22
Mha Al00a MEDIUM 5.5
CVE-2017-8186

The Bastet of some Huawei mobile phones with software of earlier than MHA-AL00BC00B231 versions has a DOS vulnerability due to the lack of parameter …

Mitigation only
Fix from $1,600 2017-11-22
Honor 5c Firmware MEDIUM 5.5
CVE-2017-8143

Wi-Fi driver of Honor 5C and P9 Lite Huawei smart phones with software versions earlier than NEM-L21C432B351 and versions earlier than VNS-L21C10B381…

Mitigation only
Fix from $1,600 2017-11-22
P10 Firmware MEDIUM 5.5
CVE-2017-8145

The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-A…

Mitigation only
Fix from $1,600 2017-11-22
P10 Firmware MEDIUM 5.5
CVE-2017-8146

The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-A…

Mitigation only
Fix from $1,600 2017-11-22
Ac6005 Firmware HIGH 7.5
CVE-2017-8147

AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software…

Mitigation only
Fix from $1,950 2017-11-22
Usg9500 Firmware HIGH 7.5
CVE-2017-8167

Huawei firewall products USG9500 V500R001C50 has a DoS vulnerability.A remote attacker who controls the peer device could exploit the vulnerability b…

Mitigation only
Fix from $1,950 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8117

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of …

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8119

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of …

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8120

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of …

No fix yet
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8122

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. A…

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8123

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. A…

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8124

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. A…

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8126

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. A…

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8128

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of …

Mitigation only
Fix from $2,300 2017-11-22
Uma CRITICAL 9.8
CVE-2017-8129

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of …

Mitigation only
Fix from $2,300 2017-11-22
P9 Firmware MEDIUM 5.4
CVE-2017-2713

HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09…

Mitigation only
Fix from $1,600 2017-11-22
Dp300 Firmware HIGH 8.8
CVE-2017-2722

DP300 V500R002C00,TE60 with software V100R001C01, V100R001C10, V100R003C00, V500R002C00 and V600R006C00,TP3106 with software V100R001C06 and V100R002…

Mitigation only
Fix from $1,950 2017-11-22
P9 Plus Firmware MEDIUM 5.5
CVE-2017-2731

The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a us…

Mitigation only
Fix from $1,600 2017-11-22
Higame MEDIUM 5.5
CVE-2017-2709

HiGame with software earlier than 7.3.0 versions, SkyTone with software earlier than 8.1.1 versions have a DoS Vulnerability. An attacker tricks a us…

Fix: 7.3.0 / 8.1.1+
Fix from $1,600 2017-11-22
P9 Plus Firmware MEDIUM 5.5
CVE-2017-2711

P9 Plus smartphones with software earlier than VIE-AL10C00B352 versions have an input validation vulnerability in the touchscreen Driver. An attacker…

Mitigation only
Fix from $1,600 2017-11-22
Tofino Xenon Security Appliance Firmware CRITICAL 9.8
CVE-2017-11402

An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Design flaws in OPC classic and in custom netfi…

Fix: after 3.1.0
Fix from $2,300 2017-11-20
Snap7 Server HIGH 7.5
CVE-2017-1000230

The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap…

Mitigation only
Fix from $1,950 2017-11-17
Debian Linux CRITICAL 10.0
CVE-2017-16845

hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.

Fix: after 2.11.2
Fix from $2,300 2017-11-17
Quickerbb CRITICAL 9.8
CVE-2017-1000169

QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of …

Fix: after 0.7.2
Fix from $2,300 2017-11-17
Eds G512e Firmware HIGH 7.5
CVE-2017-13703

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.

No fix yet
Fix from $1,950 2017-11-17
Codeigniter HIGH 7.5
CVE-2017-1000247

British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Ap…

Mitigation only
Fix from $1,950 2017-11-17
Ejs HIGH 7.5
CVE-2017-1000189

nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()

Fix: 2.5.5+
Fix from $1,950 2017-11-17
Ejs CRITICAL 9.8
CVE-2017-1000228EPSS 6%

nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

Fix: 2.5.3+
Fix from $2,300 2017-11-17