Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2016-9394 The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a c… Jasper after 1.900.16 Fix from $1,6002017-03-23 MEDIUM 5.5 CVE-2016-9395 The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a c… Jasper after 1.900.24 Fix from $1,6002017-03-23 MEDIUM 6.5 CVE-2016-5755 NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 6.5 CVE-2016-9168 A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjack… Edirectory after 9.0.1 Fix from $1,6002017-03-23 HIGH 8.8 CVE-2017-7235 An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code ag… Cloudflare Scrape Patch available Fix from $1,9502017-03-23 HIGH 8.1 CVE-2017-3852 A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, rem… Iox Mitigation only Fix from $1,9502017-03-22 HIGH 8.8 CVE-2017-3858 A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are exe… Ios Xe Mitigation only Fix from $1,9502017-03-22 HIGH 7.4 CVE-2017-3849 A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS X… iOS Mitigation only Fix from $1,9502017-03-21 MEDIUM 5.9 CVE-2017-3850 A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 through 15.6) and Cisco IOS XE Software (3.7 thr… iOS Mitigation only Fix from $1,6002017-03-21 HIGH 8.1 CVE-2016-4927 Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicatin… Junos Space after 15.2 Fix from $1,9502017-03-20 HIGH 7.1 CVE-2016-6816EPSS 47% The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reque… Tomcat No fix yet Fix from $1,9502017-03-20 MEDIUM 5.5 CVE-2017-6837 WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via vectors related to a large numb… Audiofile Patch available Fix from $1,6002017-03-20 HIGH 7.5 CVE-2014-9851 ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). Ubuntu Linux Patch available Fix from $1,9502017-03-20 MEDIUM 5.3 CVE-2017-3875 An Access-Control Filtering Mechanisms Bypass vulnerability in certain access-control filtering mechanisms on Cisco Nexus 7000 Series Switches could … Nx Os Mitigation only Fix from $1,6002017-03-17 CRITICAL 9.8 CVE-2017-3881 KEVEPSS 99% A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,… iOS after 15.1 Fix from $2,3002017-03-17 CRITICAL 9.8 CVE-2014-8705 PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the … Wondercms Patch available Fix from $2,3002017-03-17 MEDIUM 5.3 CVE-2017-6955 An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and th… Invite Anyone after 1.3.13 Fix from $1,6002017-03-17 MEDIUM 5.5 CVE-2017-6961 An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is … Apng2gif Mitigation only Fix from $1,6002017-03-17 HIGH 8.1 CVE-2017-0148 KEVEPSS 99% The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win… Server Message Block 4.0e+ Fix from $1,9502017-03-17 MEDIUM 5.4 CVE-2017-0076 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511… Windows 10 Patch available Fix from $1,6002017-03-17 HIGH 7.6 CVE-2017-0095EPSS 5% Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to e… Windows 10 Patch available Fix from $1,9502017-03-17 MEDIUM 5.4 CVE-2017-0097 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511… Windows 10 Patch available Fix from $1,6002017-03-17 MEDIUM 5.4 CVE-2017-0098 Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial o… Windows 10 Patch available Fix from $1,6002017-03-17 MEDIUM 5.4 CVE-2017-0099 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 … Windows 10 Patch available Fix from $1,6002017-03-17 HIGH 7.6 CVE-2017-0109EPSS 6% Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold,… Windows 10 Patch available Fix from $1,9502017-03-17 MEDIUM 5.4 CVE-2017-0074 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511… Windows 10 Patch available Fix from $1,6002017-03-17 MEDIUM 5.5 CVE-2017-0007EPSS 15% Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidati… Windows 10 Patch available Fix from $1,6002017-03-17 HIGH 8.6 CVE-2017-3846 A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote… Tidal Enterprise Scheduler Mitigation only Fix from $1,9502017-03-15 MEDIUM 5.5 CVE-2016-10167EPSS 6% The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of ser… Libgd after 2.2.3 Fix from $1,6002017-03-15 HIGH 7.5 CVE-2017-5359EPSS 7% EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI. Sql Iplug No fix yet Fix from $1,9502017-03-15