Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2017-12632 A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and … Nifi after 1.4.0 Fix from $1,9502018-01-23 CRITICAL 9.8 CVE-2017-15697 A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fi… Nifi after 1.4.0 Fix from $2,3002018-01-23 CRITICAL 9.8 CVE-2017-2750EPSS 6% Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterpris… L2683a Firmware 2308937_578483 / 2308937_578486+ Fix from $2,3002018-01-23 MEDIUM 5.3 CVE-2017-15105 A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u… Debian Linux 1.6.8+ Fix from $1,6002018-01-23 MEDIUM 5.3 CVE-2017-15093 When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x… Recursor after 4.0.6 Fix from $1,6002018-01-23 MEDIUM 6.5 CVE-2017-16594 This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build … Enterprise Manager Mitigation only Fix from $1,6002018-01-23 CRITICAL 9.8 CVE-2018-5955EPSS 75% An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a… Gitstack after 2.3.10 Fix from $2,3002018-01-21 HIGH 7.8 CVE-2018-5956 In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other … Zillya\! Antivirus Mitigation only Fix from $1,9502018-01-21 HIGH 7.8 CVE-2018-5957 In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other … Zillya\! Antivirus Mitigation only Fix from $1,9502018-01-21 HIGH 7.8 CVE-2018-5958 In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other … Zillya\! Antivirus Mitigation only Fix from $1,9502018-01-21 HIGH 7.5 CVE-2017-7325 Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open. Yandex Browser 16.9.0+ Fix from $1,9502018-01-19 MEDIUM 5.7 CVE-2017-17860 In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user'… Android No fix yet Fix from $1,6002018-01-18 MEDIUM 6.5 CVE-2017-12197 It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di… Debian Linux after 1.8 Fix from $1,6002018-01-18 HIGH 7.5 CVE-2018-0090 A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote… Nx Os Mitigation only Fix from $1,9502018-01-18 MEDIUM 5.5 CVE-2017-5699 Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of service via UEFI APIs. Minnowboard 3 Firmware 0.65+ Fix from $1,6002018-01-18 MEDIUM 5.5 CVE-2017-16556 In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations. Antivirus 14.2.0137 / 15.1.0.53+ Fix from $1,6002018-01-16 MEDIUM 5.5 CVE-2017-17429 In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW int… Antivirus 14.2.0137 / 15.1.0.53+ Fix from $1,6002018-01-16 HIGH 7.8 CVE-2018-5713 In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified … Anti Malware No fix yet Fix from $1,9502018-01-16 HIGH 7.8 CVE-2018-5714 In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified … Anti Malware No fix yet Fix from $1,9502018-01-16 MEDIUM 5.4 CVE-2016-0207 IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecifie… Algo Risk Application after 5.1.0 Fix from $1,6002018-01-16 MEDIUM 6.5 CVE-2016-0215 IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of servic… Db2 Patch available Fix from $1,6002018-01-16 HIGH 7.5 CVE-2017-13194 A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android … Debian Linux Patch available Fix from $1,9502018-01-12 HIGH 7.5 CVE-2017-13198 A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1… Android Patch available Fix from $1,9502018-01-12 HIGH 7.5 CVE-2017-13214 In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process w… Android Mitigation only Fix from $1,9502018-01-12 HIGH 8.8 CVE-2017-13176 In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privileg… Android Patch available Fix from $1,9502018-01-12 HIGH 7.5 CVE-2017-13186 A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8… Android Patch available Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2015-9246 An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The … Skybox Platform 7.5.201+ Fix from $2,3002018-01-12 HIGH 8.8 CVE-2014-8166 The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to exe… Cups 1.6+ Fix from $1,9502018-01-12 HIGH 7.8 CVE-2017-15845 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmware size (ne… Android Patch available Fix from $1,9502018-01-10 MEDIUM 5.5 CVE-2014-4994 lib/gyazo/client.rb in the gyazo gem 1.0.0 for Ruby allows local users to write to arbitrary files via a symlink attack on a temporary file, related … Gyazo No fix yet Fix from $1,6002018-01-10