Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Enterprise Central Component HIGH 9.3
CVE-2015-3621

Untrusted search path vulnerability in SAP Enterprise Central Component (ECC) allows local users to gain privileges via a Trojan horse program.

No fix yet
Fix from $1,950 2015-07-16
Acrobat HIGH 7.8
CVE-2015-5091

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,950 2015-07-15
Asr 5000 Series Software MEDIUM 5.0
CVE-2015-4273

The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attacke…

Mitigation only
Fix from $1,600 2015-07-15
Windows 2003 Server MEDIUM 5.0
CVE-2015-2417EPSS 10%

OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serve…

Mitigation only
Fix from $1,600 2015-07-14
Windows 2003 Server MEDIUM 5.0
CVE-2015-2416EPSS 10%

OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serve…

Mitigation only
Fix from $1,600 2015-07-14
Pivotx HIGH 7.5
CVE-2015-5457

PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute…

Fix: after 2.3.10
Fix from $1,950 2015-07-08
Security Api Activex Sdk HIGH 7.5
CVE-2015-4648EPSS 6%

Stack-based buffer overflow in the Ipropsapi.ipropsapiCtrl.1 ActiveX control in ipropsapivideo in Panasonic Security API (PS-API) ActiveX SDK before …

Fix: after 8.10.14
Fix from $1,950 2015-07-06
Firefox MEDIUM 6.8
CVE-2015-2727

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chro…

Mitigation only
Fix from $1,600 2015-07-06
Secure Remote Services MEDIUM 5.8
CVE-2015-0543

EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-i…

Mitigation only
Fix from $1,600 2015-07-05
Namshi\/jose MEDIUM 5.0
CVE-2015-2964

NAMSHI | JOSE 5.0.0 and earlier allows remote attackers to bypass signature verification via crafted tokens in a JSON Web Tokens (JWT) header.

Fix: after 5.0.0
Fix from $1,600 2015-07-05
Libreswan MEDIUM 5.0
CVE-2015-3204

libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in …

Mitigation only
Fix from $1,600 2015-07-01
Tivoli Storage Manager Fastback HIGH 9.3
CVE-2015-1942EPSS 7%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to write to arbitrary files, and subsequently execute the…

Mitigation only
Fix from $1,950 2015-06-30
Curl MEDIUM 6.4
CVE-2015-3237EPSS 8%

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cau…

Fix: after 7.5.3.1
Fix from $1,600 2015-06-22
Nx Os MEDIUM 6.1
CVE-2015-4197

Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on th…

Mitigation only
Fix from $1,600 2015-06-20
Asr 5000 Series Software MEDIUM 5.0
CVE-2015-4201

The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows …

Mitigation only
Fix from $1,600 2015-06-20
Services MEDIUM 6.0
CVE-2015-4393

The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save …

Patch available
Fix from $1,600 2015-06-15
Blobee HIGH 7.5
CVE-2015-2962

CGI RESCUE BloBee 1.20 and earlier allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via unspecified vect…

Fix: after 1.12
Fix from $1,950 2015-06-13
Fusion HIGH 7.8
CVE-2015-2341

VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 allow attackers to cau…

Patch available
Fix from $1,950 2015-06-13
Email Security Appliance MEDIUM 5.0
CVE-2015-4184

The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intend…

Mitigation only
Fix from $1,600 2015-06-13
Xcloner MEDIUM 6.5
CVE-2014-8603EPSS 6%

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell…

No fix yet
Fix from $1,600 2015-06-10
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-4148EPSS 20%

The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property …

Fix: after 10.10.4
Fix from $1,600 2015-06-09
Linux MEDIUM 6.8
CVE-2015-3330EPSS 14%

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTT…

Patch available
Fix from $1,600 2015-06-09
Telepresence Tc Software MEDIUM 5.0
CVE-2015-0770

CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to i…

Mitigation only
Fix from $1,600 2015-06-07
Jwt MEDIUM 5.0
CVE-2015-2951

JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.

Fix: after 1.0
Fix from $1,600 2015-06-05
M 2001d Digital Tapchanger Control MEDIUM 6.4
CVE-2014-9201

Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmw…

Fix: after 04.07.00
Fix from $1,600 2015-06-05
Fusionforge HIGH 10.0
CVE-2015-0850

The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary…

Fix: after 6.0
Fix from $1,950 2015-06-02
Headend Digital Broadband Delivery System MEDIUM 6.8
CVE-2015-0759

Cross-site request forgery (CSRF) vulnerability in Cisco Headend Digital Broadband Delivery System allows remote attackers to hijack the authenticati…

Mitigation only
Fix from $1,600 2015-06-02
Jackrabbit MEDIUM 6.4
CVE-2015-1833EPSS 51%

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before …

Fix: after 2.0.5
Fix from $1,600 2015-05-29
Wireless Lan Controller MEDIUM 6.1
CVE-2015-0756

Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (wireless-networking outage) v…

Mitigation only
Fix from $1,600 2015-05-29
Finesse HIGH 7.5
CVE-2015-0754

Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via…

Mitigation only
Fix from $1,950 2015-05-29