Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2015-2156 Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 mig… Netty after 3.9.7 Fix from $1,9502017-10-18 MEDIUM 6.5 CVE-2017-15591 An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (… Xen Patch available Fix from $1,6002017-10-18 HIGH 8.1 CVE-2017-3759 The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to ma… Service Framework Patch available Fix from $1,9502017-10-17 HIGH 7.5 CVE-2014-8323 buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted l… Aircrack Ng after 1.2 Fix from $1,9502017-10-17 HIGH 7.5 CVE-2014-8324 network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted le… Aircrack Ng after 1.2 Fix from $1,9502017-10-17 MEDIUM 6.1 CVE-2014-9678 FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter. Flexpaper after 2.3.0 Fix from $1,6002017-10-17 CRITICAL 9.8 CVE-2014-9733 nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified impact via unknown vectors. Nw.js after 0.11.4 Fix from $2,3002017-10-17 HIGH 7.8 CVE-2017-0316 In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from… Geforce Experience 3.10.0.55+ Fix from $1,9502017-10-16 HIGH 8.8 CVE-2016-4461EPSS 8% Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva… Struts 2.3.29+ Fix from $1,9502017-10-16 MEDIUM 5.9 CVE-2017-10610 On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause the flowd process to crash. Repeated crashes of th… Junos Mitigation only Fix from $1,6002017-10-13 CRITICAL 9.8 CVE-2017-10615 A vulnerability in the pluggable authentication module (PAM) of Juniper Networks Junos OS may allow an unauthenticated network based attacker to pote… Junos Mitigation only Fix from $2,3002017-10-13 HIGH 8.8 CVE-2017-15012EPSS 6% OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-comm… Documentum Content Server after 7.3 Fix from $1,9502017-10-13 HIGH 8.8 CVE-2017-11762EPSS 15% The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… Windows 10 Patch available Fix from $1,9502017-10-13 HIGH 8.8 CVE-2017-11763EPSS 15% The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… Windows 10 Patch available Fix from $1,9502017-10-13 CRITICAL 9.8 CVE-2017-11771EPSS 55% The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, … Windows 10 Patch available Fix from $2,3002017-10-13 HIGH 7.5 CVE-2017-11781EPSS 12% The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2… Windows 10 Patch available Fix from $1,9502017-10-13 HIGH 7.8 CVE-2017-11782 The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an… Windows 10 Patch available Fix from $1,9502017-10-13 HIGH 8.8 CVE-2017-15285 X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check … X Cart No fix yet Fix from $1,9502017-10-12 HIGH 7.4 CVE-2017-8025 RSA Archer GRC Platform prior to 6.2.0.5 is affected by an arbitrary file upload vulnerability. A remote unauthenticated attacker may potentially exp… Archer Grc Platform after 6.2.0.4 Fix from $1,9502017-10-11 HIGH 7.5 CVE-2017-5721 Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows loc… Nuc7i7bnh Firmware Patch available Fix from $1,9502017-10-11 CRITICAL 9.8 CVE-2017-8994EPSS 6% A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely. Operations Orchestration after 10.70 Fix from $2,3002017-10-10 MEDIUM 5.0 CVE-2017-15185 plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allo… Libmp3splt No fix yet Fix from $1,6002017-10-09 HIGH 7.5 CVE-2017-9272 The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack. Bi Directional Driver after 4.0.2.0 Fix from $1,9502017-10-06 HIGH 7.5 CVE-2017-1002153 Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission. Koji Patch available Fix from $1,9502017-10-06 HIGH 7.5 CVE-2017-14087EPSS 7% A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attac… Officescan No fix yet Fix from $1,9502017-10-06 HIGH 8.6 CVE-2017-12244 A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker t… Secure Firewall Management Center Mitigation only Fix from $1,9502017-10-05 HIGH 8.6 CVE-2017-12246EPSS 5% A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthe… Adaptive Security Appliance Software Mitigation only Fix from $1,9502017-10-05 MEDIUM 5.3 CVE-2017-12264 A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS)… Meeting Server Mitigation only Fix from $1,6002017-10-05 HIGH 7.3 CVE-2017-1541 A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy and javaws.policy files from … Aix Mitigation only Fix from $1,9502017-10-04 HIGH 7.5 CVE-2017-8018 EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability that could potentially be ex… Appsync after 3.5 Fix from $1,9502017-10-03