Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Edge MEDIUM 6.5
CVE-2017-8611EPSS 11%

Microsoft Edge on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows remote attackers to spoof web content via a crafted…

Patch available
Fix from $1,600 2017-07-11
Windows 10 HIGH 7.0
CVE-2017-8566

Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) imprope…

Patch available
Fix from $1,950 2017-07-11
.net Framework HIGH 7.5
CVE-2017-8585EPSS 9%

Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in deni…

Patch available
Fix from $1,950 2017-07-11
Cubeone Firmware HIGH 7.5
CVE-2017-7730

iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.

No fix yet
Fix from $1,950 2017-07-11
Wide Area Application Services MEDIUM 5.3
CVE-2017-6727

A vulnerability in the Server Message Block (SMB) protocol of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,600 2017-07-10
Firesight System Software MEDIUM 6.7
CVE-2017-6735

A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute ar…

Mitigation only
Fix from $1,600 2017-07-10
Struts CRITICAL 9.8
CVE-2017-9791 KEVEPSS 99%

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Act…

Patch available
Fix from $2,300 2017-07-10
PHP HIGH 7.5
CVE-2016-10397

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostn…

Fix: after 5.6.27
Fix from $1,950 2017-07-10
Ncurses HIGH 7.5
CVE-2017-11112

In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial o…

Mitigation only
Fix from $1,950 2017-07-08
Debian Linux MEDIUM 5.9
CVE-2017-11104

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key na…

Fix: after 2.4.4
Fix from $1,600 2017-07-08
Swftools HIGH 8.8
CVE-2017-11098

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

No fix yet
Fix from $1,950 2017-07-07
Swftools HIGH 8.8
CVE-2017-11099

When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.

No fix yet
Fix from $1,950 2017-07-07
Graphicsmagick HIGH 7.5
CVE-2017-11102

The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during…

Patch available
Fix from $1,950 2017-07-07
Nitro Pro MEDIUM 5.5
CVE-2017-7950

Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

Fix: after 11.0.3
Fix from $1,600 2017-07-07
Android MEDIUM 5.5
CVE-2017-0689

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID…

Mitigation only
Fix from $1,600 2017-07-06
Android MEDIUM 5.5
CVE-2017-0694

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. And…

No fix yet
Fix from $1,600 2017-07-06
Android MEDIUM 5.5
CVE-2017-0696

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207120.

Mitigation only
Fix from $1,600 2017-07-06
Android HIGH 7.8
CVE-2017-0665

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Andr…

Mitigation only
Fix from $1,950 2017-07-06
Android HIGH 7.8
CVE-2017-0667

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID:…

Mitigation only
Fix from $1,950 2017-07-06
Android MEDIUM 5.5
CVE-2017-0672

A denial of service vulnerability in the Android libraries. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-34778578.

No fix yet
Fix from $1,600 2017-07-06
Android HIGH 7.8
CVE-2017-0674

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-342311…

Patch available
Fix from $1,950 2017-07-06
Android HIGH 7.8
CVE-2017-0675

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.

Patch available
Fix from $1,950 2017-07-06
Android HIGH 7.8
CVE-2017-0676

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Androi…

Mitigation only
Fix from $1,950 2017-07-06
Debian Linux HIGH 7.5
CVE-2017-9524

The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a d…

Fix: after 2.9.1
Fix from $1,950 2017-07-06
Websphere Mq MEDIUM 6.5
CVE-2017-1236

IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM …

Mitigation only
Fix from $1,600 2017-07-06
Xen CRITICAL 10.0
CVE-2017-10918

Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access…

Fix: after 4.8.1
Fix from $2,300 2017-07-05
Xen MEDIUM 6.5
CVE-2017-10923

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervis…

Mitigation only
Fix from $1,600 2017-07-05
Ios Xr MEDIUM 6.7
CVE-2017-6718

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Inform…

Mitigation only
Fix from $1,600 2017-07-04
Ios Xr MEDIUM 6.7
CVE-2017-6719

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating …

Mitigation only
Fix from $1,600 2017-07-04
Wide Area Application Services MEDIUM 5.3
CVE-2017-6721

A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, re…

Mitigation only
Fix from $1,600 2017-07-04