Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Jasper MEDIUM 5.5
CVE-2016-9394

The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a c…

Fix: after 1.900.16
Fix from $1,600 2017-03-23
Jasper MEDIUM 5.5
CVE-2016-9395

The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a c…

Fix: after 1.900.24
Fix from $1,600 2017-03-23
Access Manager MEDIUM 6.5
CVE-2016-5755

NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the…

Mitigation only
Fix from $1,600 2017-03-23
Edirectory MEDIUM 6.5
CVE-2016-9168

A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjack…

Fix: after 9.0.1
Fix from $1,600 2017-03-23
Cloudflare Scrape HIGH 8.8
CVE-2017-7235

An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code ag…

Patch available
Fix from $1,950 2017-03-23
Iox HIGH 8.1
CVE-2017-3852

A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, rem…

Mitigation only
Fix from $1,950 2017-03-22
Ios Xe HIGH 8.8
CVE-2017-3858

A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are exe…

Mitigation only
Fix from $1,950 2017-03-22
iOS HIGH 7.4
CVE-2017-3849

A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS X…

Mitigation only
Fix from $1,950 2017-03-21
iOS MEDIUM 5.9
CVE-2017-3850

A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 through 15.6) and Cisco IOS XE Software (3.7 thr…

Mitigation only
Fix from $1,600 2017-03-21
Junos Space HIGH 8.1
CVE-2016-4927

Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicatin…

Fix: after 15.2
Fix from $1,950 2017-03-20
Tomcat HIGH 7.1
CVE-2016-6816EPSS 47%

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reque…

No fix yet
Fix from $1,950 2017-03-20
Audiofile MEDIUM 5.5
CVE-2017-6837

WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via vectors related to a large numb…

Patch available
Fix from $1,600 2017-03-20
Ubuntu Linux HIGH 7.5
CVE-2014-9851

ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).

Patch available
Fix from $1,950 2017-03-20
Nx Os MEDIUM 5.3
CVE-2017-3875

An Access-Control Filtering Mechanisms Bypass vulnerability in certain access-control filtering mechanisms on Cisco Nexus 7000 Series Switches could …

Mitigation only
Fix from $1,600 2017-03-17
iOS CRITICAL 9.8
CVE-2017-3881 KEVEPSS 99%

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,…

Fix: after 15.1
Fix from $2,300 2017-03-17
Wondercms CRITICAL 9.8
CVE-2014-8705

PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the …

Patch available
Fix from $2,300 2017-03-17
Invite Anyone MEDIUM 5.3
CVE-2017-6955

An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and th…

Fix: after 1.3.13
Fix from $1,600 2017-03-17
Apng2gif MEDIUM 5.5
CVE-2017-6961

An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is …

Mitigation only
Fix from $1,600 2017-03-17
Server Message Block HIGH 8.1
CVE-2017-0148 KEVEPSS 99%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Fix: 4.0e+
Fix from $1,950 2017-03-17
Windows 10 MEDIUM 5.4
CVE-2017-0076

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511…

Patch available
Fix from $1,600 2017-03-17
Windows 10 HIGH 7.6
CVE-2017-0095EPSS 5%

Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to e…

Patch available
Fix from $1,950 2017-03-17
Windows 10 MEDIUM 5.4
CVE-2017-0097

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 5.4
CVE-2017-0098

Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial o…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 5.4
CVE-2017-0099

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 …

Patch available
Fix from $1,600 2017-03-17
Windows 10 HIGH 7.6
CVE-2017-0109EPSS 6%

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold,…

Patch available
Fix from $1,950 2017-03-17
Windows 10 MEDIUM 5.4
CVE-2017-0074

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 5.5
CVE-2017-0007EPSS 15%

Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidati…

Patch available
Fix from $1,600 2017-03-17
Tidal Enterprise Scheduler HIGH 8.6
CVE-2017-3846

A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote…

Mitigation only
Fix from $1,950 2017-03-15
Libgd MEDIUM 5.5
CVE-2016-10167EPSS 6%

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of ser…

Fix: after 2.2.3
Fix from $1,600 2017-03-15
Sql Iplug HIGH 7.5
CVE-2017-5359EPSS 7%

EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.

No fix yet
Fix from $1,950 2017-03-15