Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Netty HIGH 7.5
CVE-2015-2156

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 mig…

Fix: after 3.9.7
Fix from $1,950 2017-10-18
Xen MEDIUM 6.5
CVE-2017-15591

An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (…

Patch available
Fix from $1,600 2017-10-18
Service Framework HIGH 8.1
CVE-2017-3759

The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to ma…

Patch available
Fix from $1,950 2017-10-17
Aircrack Ng HIGH 7.5
CVE-2014-8323

buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted l…

Fix: after 1.2
Fix from $1,950 2017-10-17
Aircrack Ng HIGH 7.5
CVE-2014-8324

network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted le…

Fix: after 1.2
Fix from $1,950 2017-10-17
Flexpaper MEDIUM 6.1
CVE-2014-9678

FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.

Fix: after 2.3.0
Fix from $1,600 2017-10-17
Nw.js CRITICAL 9.8
CVE-2014-9733

nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified impact via unknown vectors.

Fix: after 0.11.4
Fix from $2,300 2017-10-17
Geforce Experience HIGH 7.8
CVE-2017-0316

In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from…

Fix: 3.10.0.55+
Fix from $1,950 2017-10-16
Struts HIGH 8.8
CVE-2016-4461EPSS 8%

Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…

Fix: 2.3.29+
Fix from $1,950 2017-10-16
Junos MEDIUM 5.9
CVE-2017-10610

On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause the flowd process to crash. Repeated crashes of th…

Mitigation only
Fix from $1,600 2017-10-13
Junos CRITICAL 9.8
CVE-2017-10615

A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to pote…

Mitigation only
Fix from $2,300 2017-10-13
Documentum Content Server HIGH 8.8
CVE-2017-15012EPSS 6%

OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-comm…

Fix: after 7.3
Fix from $1,950 2017-10-13
Windows 10 HIGH 8.8
CVE-2017-11762EPSS 15%

The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

Patch available
Fix from $1,950 2017-10-13
Windows 10 HIGH 8.8
CVE-2017-11763EPSS 15%

The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

Patch available
Fix from $1,950 2017-10-13
Windows 10 CRITICAL 9.8
CVE-2017-11771EPSS 55%

The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $2,300 2017-10-13
Windows 10 HIGH 7.5
CVE-2017-11781EPSS 12%

The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2017-10-13
Windows 10 HIGH 7.8
CVE-2017-11782

The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an…

Patch available
Fix from $1,950 2017-10-13
X Cart HIGH 8.8
CVE-2017-15285

X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check …

No fix yet
Fix from $1,950 2017-10-12
Archer Grc Platform HIGH 7.4
CVE-2017-8025

RSA Archer GRC Platform prior to 6.2.0.5 is affected by an arbitrary file upload vulnerability. A remote unauthenticated attacker may potentially exp…

Fix: after 6.2.0.4
Fix from $1,950 2017-10-11
Nuc7i7bnh Firmware HIGH 7.5
CVE-2017-5721

Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows loc…

Patch available
Fix from $1,950 2017-10-11
Operations Orchestration CRITICAL 9.8
CVE-2017-8994EPSS 6%

A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.

Fix: after 10.70
Fix from $2,300 2017-10-10
Libmp3splt MEDIUM 5.0
CVE-2017-15185

plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allo…

No fix yet
Fix from $1,600 2017-10-09
Bi Directional Driver HIGH 7.5
CVE-2017-9272

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.

Fix: after 4.0.2.0
Fix from $1,950 2017-10-06
Koji HIGH 7.5
CVE-2017-1002153

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

Patch available
Fix from $1,950 2017-10-06
Officescan HIGH 7.5
CVE-2017-14087EPSS 7%

A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attac…

No fix yet
Fix from $1,950 2017-10-06
Secure Firewall Management Center HIGH 8.6
CVE-2017-12244

A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker t…

Mitigation only
Fix from $1,950 2017-10-05
Adaptive Security Appliance Software HIGH 8.6
CVE-2017-12246EPSS 5%

A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthe…

Mitigation only
Fix from $1,950 2017-10-05
Meeting Server MEDIUM 5.3
CVE-2017-12264

A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…

Mitigation only
Fix from $1,600 2017-10-05
Aix HIGH 7.3
CVE-2017-1541

A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from …

Mitigation only
Fix from $1,950 2017-10-04
Appsync HIGH 7.5
CVE-2017-8018

EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability that could potentially be ex…

Fix: after 3.5
Fix from $1,950 2017-10-03