Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Joomla\! HIGH 8.1
CVE-2016-8870EPSS 81%

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has…

Fix: after 3.6.3
Fix from $1,950 2016-11-04
Joomla\! CRITICAL 9.8
CVE-2016-8869EPSS 97%

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attacker…

Fix: after 3.6.3
Fix from $2,300 2016-11-04
Dokuwiki MEDIUM 6.5
CVE-2016-7965

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing a…

Fix: after 2016-06-26a
Fix from $1,600 2016-10-31
Email Security Appliance HIGH 7.5
CVE-2016-6372

A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Softwa…

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-6360

A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unaut…

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-6358

A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of…

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-6356

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-1481

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2016-10-28
Meeting Server CRITICAL 9.1
CVE-2016-6445

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server befo…

Mitigation only
Fix from $2,300 2016-10-27
Unified Communications Manager MEDIUM 6.5
CVE-2016-6440

The Cisco Unified Communications Manager (CUCM) may be vulnerable to data that can be displayed inside an iframe within a web page, which in turn cou…

Mitigation only
Fix from $1,600 2016-10-27
Adaptive Security Appliance Software HIGH 7.5
CVE-2016-6431

A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5) could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2016-10-27
Bind HIGH 7.5
CVE-2016-2848EPSS 26%

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) v…

Mitigation only
Fix from $1,950 2016-10-21
Linux Kernel HIGH 7.8
CVE-2015-3288

mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (pa…

Fix: 3.2.71 / 3.4.111+
Fix from $1,950 2016-10-16
Live Meeting CRITICAL 9.8
CVE-2016-7182EPSS 30%

The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R…

Mitigation only
Fix from $2,300 2016-10-14
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-7796

The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received o…

Patch available
Fix from $1,600 2016-10-13
Ubuntu Linux MEDIUM 5.5
CVE-2016-7795

The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 ha…

Fix: after 231
Fix from $1,600 2016-10-13
Automation License Manager HIGH 7.5
CVE-2016-8563

Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafte…

Fix: after 5.3
Fix from $1,950 2016-10-13
Android CRITICAL 9.8
CVE-2016-6696

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6693

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android CRITICAL 9.8
CVE-2016-6694

sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or…

Fix: after 7.0
Fix from $2,300 2016-10-10
Android HIGH 7.8
CVE-2016-6674

system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via a crafted application, aka internal bug 30445380.

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3937

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 300309…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android HIGH 7.8
CVE-2016-3936

The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 300190…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android MEDIUM 5.5
CVE-2016-3920

id3/ID3.cpp in libstagefright in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allo…

Patch available
Fix from $1,600 2016-10-10
Filedownload HIGH 8.2
CVE-2015-1000002

Open Proxy in filedownload v1.4 wordpress plugin

No fix yet
Fix from $1,950 2016-10-06
Secure Firewall Management Center HIGH 8.8
CVE-2016-6433EPSS 76%

The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary command…

No fix yet
Fix from $1,950 2016-10-06
iOS HIGH 7.5
CVE-2016-6422

Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM sh…

Mitigation only
Fix from $1,950 2016-10-06
Nx Os MEDIUM 6.5
CVE-2016-1454

Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote atta…

Fix: 5.2 / 6.0+
Fix from $1,600 2016-10-06
Unified Contact Center Express HIGH 7.5
CVE-2016-6426

The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Expres…

Mitigation only
Fix from $1,950 2016-10-05
iOS HIGH 8.1
CVE-2016-6380

The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive inform…

Mitigation only
Fix from $1,950 2016-10-05