Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2017-14771 Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-su… Skybox Manager Client Application after 8.5.500 Fix from $1,6002017-10-03 HIGH 7.5 CVE-2017-13704EPSS 64% In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is … Ubuntu Linux after 2.77 Fix from $1,9502017-10-03 HIGH 7.5 CVE-2017-14935 Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive inf… Pulse One On Premise Patch available Fix from $1,9502017-09-30 HIGH 7.5 CVE-2017-14944 Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060. Proget after 4.7.13 Fix from $1,9502017-09-30 CRITICAL 9.8 CVE-2017-12240 KEVEPSS 14% The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remot… iOS after 15.6 Fix from $2,3002017-09-29 MEDIUM 6.5 CVE-2017-12222 A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch… Ios Xe Mitigation only Fix from $1,6002017-09-29 HIGH 8.8 CVE-2017-12226 A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Super… Ios Xe Mitigation only Fix from $1,9502017-09-29 MEDIUM 5.9 CVE-2017-12228 A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauth… iOS after 15.4 Fix from $1,6002017-09-29 HIGH 7.5 CVE-2017-12233 KEVEPSS 7% Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthen… iOS after 15.6 Fix from $1,9502017-09-29 HIGH 7.5 CVE-2017-12234 KEVEPSS 7% Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthen… iOS after 15.6 Fix from $1,9502017-09-29 HIGH 7.5 CVE-2017-12235 KEVEPSS 7% A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an un… iOS after 15.6 Fix from $1,9502017-09-29 HIGH 7.5 CVE-2015-3138 print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash). Tcpdump after 4.7.3 Fix from $1,9502017-09-28 MEDIUM 5.5 CVE-2017-1000252 The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or cr… Linux Kernel after 4.13.3 Fix from $1,6002017-09-26 CRITICAL 9.8 CVE-2012-6696 inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012… Inspircd after 2.0.5 Fix from $2,3002017-09-25 MEDIUM 5.5 CVE-2010-3049 Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot). iOS after 12.2 Fix from $1,6002017-09-25 MEDIUM 6.5 CVE-2010-3050 Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot). iOS after 12.2 Fix from $1,6002017-09-25 HIGH 7.5 CVE-2015-7318 Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses. Plone Patch available Fix from $1,9502017-09-25 MEDIUM 6.1 CVE-2017-1551 IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a … Api Connect Patch available Fix from $1,6002017-09-25 HIGH 7.8 CVE-2017-6268 NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed fro… Gpu Driver Mitigation only Fix from $1,9502017-09-22 HIGH 7.8 CVE-2017-6269 NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed f… Gpu Driver Mitigation only Fix from $1,9502017-09-22 HIGH 7.8 CVE-2017-6272 NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly v… Gpu Driver after 362.00 Fix from $1,9502017-09-22 HIGH 7.8 CVE-2017-6277 NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed fro… Gpu Driver Mitigation only Fix from $1,9502017-09-22 HIGH 8.1 CVE-2017-14650 A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" uti… Horde Image Api Patch available Fix from $1,9502017-09-21 HIGH 8.0 CVE-2017-14320 Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files. Helpdesk Mx after 1.5.2 Fix from $1,9502017-09-21 HIGH 8.8 CVE-2017-14635 In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistic… Otrs Mitigation only Fix from $1,9502017-09-21 HIGH 8.8 CVE-2017-12214 A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voi… Unified Customer Voice Portal Mitigation only Fix from $1,9502017-09-21 HIGH 7.1 CVE-2017-12215 A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticate… Asyncos Mitigation only Fix from $1,9502017-09-21 MEDIUM 5.3 CVE-2017-12250 A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an… Wide Area Application Services Mitigation only Fix from $1,6002017-09-21 HIGH 7.8 CVE-2017-12252 A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potent… Findit Network Discovery Utility Mitigation only Fix from $1,9502017-09-21 MEDIUM 6.7 CVE-2017-12255 A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due … Unified Computing System Mitigation only Fix from $1,6002017-09-21