Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Hanako HIGH 7.8
CVE-2017-2154

Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Packag…

Mitigation only
Fix from $1,950 2017-04-28
Appgoat MEDIUM 6.3
CVE-2017-2100

Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via un…

Fix: after 3.0.1
Fix from $1,600 2017-04-28
Gnome Shell HIGH 8.1
CVE-2017-8288

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With thes…

Patch available
Fix from $1,950 2017-04-27
Hadoop HIGH 7.3
CVE-2017-3162EPSS 5%

HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validate…

Fix: after 2.6.5
Fix from $1,950 2017-04-26
C2 Firmware MEDIUM 6.5
CVE-2017-8219

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to th…

Fix: after 0.9.1_4.2_v0032.0_build_160706
Fix from $1,600 2017-04-25
Junos HIGH 7.5
CVE-2017-2313

Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing …

Mitigation only
Fix from $1,950 2017-04-24
Junos MEDIUM 5.3
CVE-2017-2340

On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DH…

Mitigation only
Fix from $1,600 2017-04-24
Fedora CRITICAL 9.8
CVE-2016-2173EPSS 6%

org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.

Fix: 1.5.5+
Fix from $2,300 2017-04-21
Shopware CRITICAL 9.8
CVE-2016-3109EPSS 13%

The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.

Fix: after 5.1.4
Fix from $2,300 2017-04-21
Documentum Content Server HIGH 8.8
CVE-2017-7220

OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.d…

No fix yet
Fix from $1,950 2017-04-21
Adaptive Security Appliance Software HIGH 7.7
CVE-2017-6610

A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to caus…

Mitigation only
Fix from $1,950 2017-04-20
Prime Network Registrar MEDIUM 5.8
CVE-2017-6613

A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS …

Mitigation only
Fix from $1,600 2017-04-20
Integrated Management Controller Supervisor HIGH 8.8
CVE-2017-6616

A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute…

Mitigation only
Fix from $1,950 2017-04-20
Integrated Management Controller Supervisor HIGH 8.8
CVE-2017-6619

A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute…

Mitigation only
Fix from $1,950 2017-04-20
Imagemagick MEDIUM 6.5
CVE-2016-7536

magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted profile.

Fix: 6.9.4-0+
Fix from $1,600 2017-04-20
Cs Cart HIGH 8.8
CVE-2016-4862

Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to exec…

Fix: after 4.3.9
Fix from $1,950 2017-04-20
Squirrelmail HIGH 8.8
CVE-2017-7692EPSS 28%

SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis…

No fix yet
Fix from $1,950 2017-04-20
Enterprise Backup HIGH 8.8
CVE-2017-7283

An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /a…

Fix: after 9.1.1
Fix from $1,950 2017-04-20
Linux Kernel HIGH 7.8
CVE-2017-7979

The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlatt…

Patch available
Fix from $1,950 2017-04-19
Imagemagick MEDIUM 6.5
CVE-2014-9907

coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS file.

Fix: 6.9.4-0+
Fix from $1,600 2017-04-19
Linux Kernel HIGH 7.5
CVE-2017-7645EPSS 6%

The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) …

Fix: 3.2.89 / 3.10.107+
Fix from $1,950 2017-04-18
Api Connect HIGH 7.3
CVE-2017-1161

IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Deve…

Mitigation only
Fix from $1,950 2017-04-17
Capnproto HIGH 7.5
CVE-2017-7892

Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit l…

Fix: after 0.5.3
Fix from $1,950 2017-04-17
Traffic Server HIGH 7.5
CVE-2017-5659

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

Fix: after 6.2.0
Fix from $1,950 2017-04-17
Privilege Manager HIGH 7.2
CVE-2017-6554EPSS 13%

pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and co…

No fix yet
Fix from $1,950 2017-04-14
Wolf Cms HIGH 8.8
CVE-2015-6567EPSS 9%

Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does n…

Fix: after 0.8.3
Fix from $1,950 2017-04-14
Wolf Cms HIGH 8.8
CVE-2015-6568EPSS 9%

Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does n…

Fix: after 0.8.3
Fix from $1,950 2017-04-14
Pan Os HIGH 7.8
CVE-2017-7218

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request p…

Fix: after 7.1.8
Fix from $1,950 2017-04-14
Traps HIGH 7.5
CVE-2017-7408

Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revo…

Fix: after 3.4.3
Fix from $1,950 2017-04-14
Mxview HIGH 7.5
CVE-2017-7456EPSS 23%

Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

No fix yet
Fix from $1,950 2017-04-14