Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Telepresence Video Communication Server MEDIUM 6.5
CVE-2016-1444

The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.…

Mitigation only
Fix from $1,600 2016-07-07
Prime Infrastructure HIGH 8.8
CVE-2016-1442

The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via …

Mitigation only
Fix from $1,950 2016-07-07
Enterprise Linux MEDIUM 6.5
CVE-2016-6170EPSS 41%

ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary D…

Fix: after 9.10.3
Fix from $1,600 2016-07-06
Struts MEDIUM 5.3
CVE-2016-4465EPSS 10%

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…

Mitigation only
Fix from $1,600 2016-07-04
Struts CRITICAL 9.8
CVE-2016-4438EPSS 17%

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

Mitigation only
Fix from $2,300 2016-07-04
Struts HIGH 7.5
CVE-2016-4433EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …

Mitigation only
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2016-4431EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …

Mitigation only
Fix from $1,950 2016-07-04
Tomcat HIGH 7.5
CVE-2016-3092EPSS 36%

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.…

Fix: after 1.3.1
Fix from $1,950 2016-07-04
Struts HIGH 8.2
CVE-2016-1182EPSS 26%

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to con…

Patch available
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2015-0899EPSS 21%

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modi…

Patch available
Fix from $1,950 2016-07-04
Epc3928 Firmware HIGH 7.5
CVE-2016-1336EPSS 9%

goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter…

No fix yet
Fix from $1,950 2016-07-03
Epc3928 Firmware HIGH 7.5
CVE-2016-1328EPSS 9%

goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless paramete…

No fix yet
Fix from $1,950 2016-07-03
Cloud Network Automation Provisioner HIGH 8.2
CVE-2016-1441

Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem…

Mitigation only
Fix from $1,950 2016-07-03
Prime Infrastructure HIGH 8.8
CVE-2016-1408

Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute ar…

Mitigation only
Fix from $1,950 2016-07-02
Norton Security HIGH 8.4
CVE-2016-3646EPSS 18%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 2016.0
Fix from $1,950 2016-06-30
Norton Security HIGH 8.4
CVE-2016-3644EPSS 18%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 2016.0
Fix from $1,950 2016-06-30
Mail Security For Microsoft Exchange HIGH 8.4
CVE-2016-2207EPSS 18%

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Syma…

Fix: after 10.6.1-3
Fix from $1,950 2016-06-30
Leap HIGH 7.5
CVE-2016-5301

The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP respon…

Fix: after 1.1
Fix from $1,950 2016-06-30
Ubuntu Linux HIGH 7.5
CVE-2015-8899

Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA re…

Fix: after 2.75
Fix from $1,950 2016-06-30
Deep Discovery Inspector HIGH 7.2
CVE-2016-5840EPSS 8%

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbit…

No fix yet
Fix from $1,950 2016-06-30
Linux Kernel HIGH 7.8
CVE-2016-5828

The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, whi…

Fix: 3.10.103 / 3.14.74+
Fix from $1,950 2016-06-27
Welcart E Commerce MEDIUM 5.6
CVE-2016-4825

The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary…

Fix: 1.8.3+
Fix from $1,600 2016-06-25
Asyncos HIGH 7.5
CVE-2016-1438

Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable co…

Mitigation only
Fix from $1,950 2016-06-23
Ip Phone 8800 Series Firmware MEDIUM 6.5
CVE-2016-1434

The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files v…

Mitigation only
Fix from $1,600 2016-06-23
Pi Sql Data Access Server 2016 MEDIUM 6.5
CVE-2016-4530

OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss)…

Mitigation only
Fix from $1,600 2016-06-19
Pi Af Server 2016 MEDIUM 6.5
CVE-2016-4518

OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.

Fix: after 2.7.0
Fix from $1,600 2016-06-19
Rv130w Wireless N Multifunction Vpn Router Firmware CRITICAL 9.8
CVE-2016-1395

The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W dev…

Mitigation only
Fix from $2,300 2016-06-19
Ios Receiver MEDIUM 6.1
CVE-2016-5433

Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

Fix: after 6.1.5
Fix from $1,600 2016-06-17
Ubuntu Linux MEDIUM 6.0
CVE-2016-2841

The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause …

Fix: after 2.5.0
Fix from $1,600 2016-06-16
Libreswan HIGH 7.5
CVE-2016-5361

programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (…

Fix: after 3.16
Fix from $1,950 2016-06-16