Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Poppler HIGH 7.8
CVE-2017-14617

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malici…

Mitigation only
Fix from $1,950 2017-09-20
Struts MEDIUM 5.9
CVE-2016-8738

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to …

Patch available
Fix from $1,600 2017-09-20
Struts CRITICAL 9.8
CVE-2017-12611EPSS 95%

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …

Patch available
Fix from $2,300 2017-09-20
Struts HIGH 7.5
CVE-2017-9793EPSS 8%

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo…

Patch available
Fix from $1,950 2017-09-20
Struts HIGH 7.5
CVE-2017-9804EPSS 8%

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us…

Patch available
Fix from $1,950 2017-09-20
Freeipa HIGH 7.5
CVE-2015-5179

FreeIPA might display user data improperly via vectors involving non-printable characters.

Fix: after 4.5.0
Fix from $1,950 2017-09-20
Feedhenry Enterprise Mobile Application Platform MEDIUM 6.5
CVE-2015-5248

Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

No fix yet
Fix from $1,600 2017-09-20
1763 L16bwa Firmware HIGH 7.5
CVE-2017-7924EPSS 21%

An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-…

Mitigation only
Fix from $1,950 2017-09-20
Debian Linux MEDIUM 6.5
CVE-2017-14604

GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .de…

Fix: 3.23.90+
Fix from $1,600 2017-09-20
Astaro Security Gateway Firmware CRITICAL 9.8
CVE-2017-6315EPSS 15%

Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.

No fix yet
Fix from $2,300 2017-09-19
Landesk Management Suite HIGH 7.2
CVE-2014-5362

The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages…

Fix: after 9.6
Fix from $1,950 2017-09-19
Vbulletin MEDIUM 6.5
CVE-2015-3419

vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vecto…

Mitigation only
Fix from $1,600 2017-09-19
Qts CRITICAL 9.8
CVE-2017-10700

In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of …

Mitigation only
Fix from $2,300 2017-09-19
Openwebif HIGH 8.8
CVE-2017-9333

OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the U…

Patch available
Fix from $1,950 2017-09-18
Poppler HIGH 7.8
CVE-2017-14518

In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.

No fix yet
Fix from $1,950 2017-09-17
Poppler HIGH 7.8
CVE-2017-14520

In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling mal…

No fix yet
Fix from $1,950 2017-09-17
Sugarcrm HIGH 8.8
CVE-2017-14509

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote fil…

Fix: after 7.7.2.2
Fix from $1,950 2017-09-17
E Recruiting HIGH 7.5
CVE-2017-14511

An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/…

Mitigation only
Fix from $1,950 2017-09-17
Linux Kernel MEDIUM 5.5
CVE-2017-14489

The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (p…

Fix: after 4.13.2
Fix from $1,600 2017-09-15
Api Connect MEDIUM 6.5
CVE-2017-1556

IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and ca…

Mitigation only
Fix from $1,600 2017-09-13
Dir 850l Firmware HIGH 7.5
CVE-2017-14430

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to …

No fix yet
Fix from $1,950 2017-09-13
Office 2007 HIGH 8.8
CVE-2017-8682EPSS 43%

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Window…

Patch available
Fix from $1,950 2017-09-13
Windows 10 HIGH 7.0
CVE-2017-8699EPSS 20%

Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold…

Patch available
Fix from $1,950 2017-09-13
Windows 10 MEDIUM 5.3
CVE-2017-8704

The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly…

Patch available
Fix from $1,600 2017-09-13
Windows 10 HIGH 7.8
CVE-2017-8714EPSS 6%

The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote co…

Patch available
Fix from $1,950 2017-09-13
Db2 MEDIUM 5.9
CVE-2017-1519

IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a p…

Patch available
Fix from $1,600 2017-09-12
Windriver HIGH 7.8
CVE-2017-14344

This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to …

Fix: after 12.5.1
Fix from $1,950 2017-09-12
Hb7024xt Firmware HIGH 7.5
CVE-2017-14335EPSS 21%

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/…

No fix yet
Fix from $1,950 2017-09-12
Imap CRITICAL 9.1
CVE-2017-14230

In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused…

Fix: after 3.0.3
Fix from $2,300 2017-09-10
Genixcms MEDIUM 5.3
CVE-2017-14231

GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username subst…

Fix: after 1.0.2
Fix from $1,600 2017-09-10