Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2017-14617 In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malici… Poppler Mitigation only Fix from $1,9502017-09-20 MEDIUM 5.9 CVE-2016-8738 In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to … Struts Patch available Fix from $1,6002017-09-20 CRITICAL 9.8 CVE-2017-12611EPSS 95% In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can … Struts Patch available Fix from $2,3002017-09-20 HIGH 7.5 CVE-2017-9793EPSS 8% The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo… Struts Patch available Fix from $1,9502017-09-20 HIGH 7.5 CVE-2017-9804EPSS 8% In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us… Struts Patch available Fix from $1,9502017-09-20 HIGH 7.5 CVE-2015-5179 FreeIPA might display user data improperly via vectors involving non-printable characters. Freeipa after 4.5.0 Fix from $1,9502017-09-20 MEDIUM 6.5 CVE-2015-5248 Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. Feedhenry Enterprise Mobile Application Platform No fix yet Fix from $1,6002017-09-20 HIGH 7.5 CVE-2017-7924EPSS 21% An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-… 1763 L16bwa Firmware Mitigation only Fix from $1,9502017-09-20 MEDIUM 6.5 CVE-2017-14604 GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .de… Debian Linux 3.23.90+ Fix from $1,6002017-09-20 CRITICAL 9.8 CVE-2017-6315EPSS 15% Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. Astaro Security Gateway Firmware No fix yet Fix from $2,3002017-09-19 HIGH 7.2 CVE-2014-5362 The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages… Landesk Management Suite after 9.6 Fix from $1,9502017-09-19 MEDIUM 6.5 CVE-2015-3419 vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vecto… Vbulletin Mitigation only Fix from $1,6002017-09-19 CRITICAL 9.8 CVE-2017-10700 In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of … Qts Mitigation only Fix from $2,3002017-09-19 HIGH 8.8 CVE-2017-9333 OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the U… Openwebif Patch available Fix from $1,9502017-09-18 HIGH 7.8 CVE-2017-14518 In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document. Poppler No fix yet Fix from $1,9502017-09-17 HIGH 7.8 CVE-2017-14520 In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling mal… Poppler No fix yet Fix from $1,9502017-09-17 HIGH 8.8 CVE-2017-14509 An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote fil… Sugarcrm after 7.7.2.2 Fix from $1,9502017-09-17 HIGH 7.5 CVE-2017-14511 An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/… E Recruiting Mitigation only Fix from $1,9502017-09-17 MEDIUM 5.5 CVE-2017-14489 The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (p… Linux Kernel after 4.13.2 Fix from $1,6002017-09-15 MEDIUM 6.5 CVE-2017-1556 IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and ca… Api Connect Mitigation only Fix from $1,6002017-09-13 HIGH 7.5 CVE-2017-14430 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to … Dir 850l Firmware No fix yet Fix from $1,9502017-09-13 HIGH 8.8 CVE-2017-8682EPSS 43% Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Window… Office 2007 Patch available Fix from $1,9502017-09-13 HIGH 7.0 CVE-2017-8699EPSS 20% Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… Windows 10 Patch available Fix from $1,9502017-09-13 MEDIUM 5.3 CVE-2017-8704 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly… Windows 10 Patch available Fix from $1,6002017-09-13 HIGH 7.8 CVE-2017-8714EPSS 6% The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote co… Windows 10 Patch available Fix from $1,9502017-09-13 MEDIUM 5.9 CVE-2017-1519 IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a p… Db2 Patch available Fix from $1,6002017-09-12 HIGH 7.8 CVE-2017-14344 This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to … Windriver after 12.5.1 Fix from $1,9502017-09-12 HIGH 7.5 CVE-2017-14335EPSS 21% On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/… Hb7024xt Firmware No fix yet Fix from $1,9502017-09-12 CRITICAL 9.1 CVE-2017-14230 In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused… Imap after 3.0.3 Fix from $2,3002017-09-10 MEDIUM 5.3 CVE-2017-14231 GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username subst… Genixcms after 1.0.2 Fix from $1,6002017-09-10