Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Skybox Manager Client Application MEDIUM 5.5
CVE-2017-14771

Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-su…

Fix: after 8.5.500
Fix from $1,600 2017-10-03
Ubuntu Linux HIGH 7.5
CVE-2017-13704EPSS 64%

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is …

Fix: after 2.77
Fix from $1,950 2017-10-03
Pulse One On Premise HIGH 7.5
CVE-2017-14935

Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive inf…

Patch available
Fix from $1,950 2017-09-30
Proget HIGH 7.5
CVE-2017-14944

Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.

Fix: after 4.7.13
Fix from $1,950 2017-09-30
iOS CRITICAL 9.8
CVE-2017-12240 KEVEPSS 14%

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remot…

Fix: after 15.6
Fix from $2,300 2017-09-29
Ios Xe MEDIUM 6.5
CVE-2017-12222

A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch…

Mitigation only
Fix from $1,600 2017-09-29
Ios Xe HIGH 8.8
CVE-2017-12226

A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Super…

Mitigation only
Fix from $1,950 2017-09-29
iOS MEDIUM 5.9
CVE-2017-12228

A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauth…

Fix: after 15.4
Fix from $1,600 2017-09-29
iOS HIGH 7.5
CVE-2017-12233 KEVEPSS 7%

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthen…

Fix: after 15.6
Fix from $1,950 2017-09-29
iOS HIGH 7.5
CVE-2017-12234 KEVEPSS 7%

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthen…

Fix: after 15.6
Fix from $1,950 2017-09-29
iOS HIGH 7.5
CVE-2017-12235 KEVEPSS 7%

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an un…

Fix: after 15.6
Fix from $1,950 2017-09-29
Tcpdump HIGH 7.5
CVE-2015-3138

print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).

Fix: after 4.7.3
Fix from $1,950 2017-09-28
Linux Kernel MEDIUM 5.5
CVE-2017-1000252

The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or cr…

Fix: after 4.13.3
Fix from $1,600 2017-09-26
Inspircd CRITICAL 9.8
CVE-2012-6696

inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012…

Fix: after 2.0.5
Fix from $2,300 2017-09-25
iOS MEDIUM 5.5
CVE-2010-3049

Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).

Fix: after 12.2
Fix from $1,600 2017-09-25
iOS MEDIUM 6.5
CVE-2010-3050

Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot).

Fix: after 12.2
Fix from $1,600 2017-09-25
Plone HIGH 7.5
CVE-2015-7318

Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.

Patch available
Fix from $1,950 2017-09-25
Api Connect MEDIUM 6.1
CVE-2017-1551

IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Patch available
Fix from $1,600 2017-09-25
Gpu Driver HIGH 7.8
CVE-2017-6268

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed fro…

Mitigation only
Fix from $1,950 2017-09-22
Gpu Driver HIGH 7.8
CVE-2017-6269

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed f…

Mitigation only
Fix from $1,950 2017-09-22
Gpu Driver HIGH 7.8
CVE-2017-6272

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly v…

Fix: after 362.00
Fix from $1,950 2017-09-22
Gpu Driver HIGH 7.8
CVE-2017-6277

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed fro…

Mitigation only
Fix from $1,950 2017-09-22
Horde Image Api HIGH 8.1
CVE-2017-14650

A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" uti…

Patch available
Fix from $1,950 2017-09-21
Helpdesk Mx HIGH 8.0
CVE-2017-14320

Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.

Fix: after 1.5.2
Fix from $1,950 2017-09-21
Otrs HIGH 8.8
CVE-2017-14635

In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistic…

Mitigation only
Fix from $1,950 2017-09-21
Unified Customer Voice Portal HIGH 8.8
CVE-2017-12214

A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voi…

Mitigation only
Fix from $1,950 2017-09-21
Asyncos HIGH 7.1
CVE-2017-12215

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticate…

Mitigation only
Fix from $1,950 2017-09-21
Wide Area Application Services MEDIUM 5.3
CVE-2017-12250

A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an…

Mitigation only
Fix from $1,600 2017-09-21
Findit Network Discovery Utility HIGH 7.8
CVE-2017-12252

A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potent…

Mitigation only
Fix from $1,950 2017-09-21
Unified Computing System MEDIUM 6.7
CVE-2017-12255

A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due …

Mitigation only
Fix from $1,600 2017-09-21