Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2017-3792EPSS 6% A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthentica… Telepresence Mcu Software Mitigation only Fix from $2,3002017-02-01 HIGH 7.8 CVE-2016-4038 Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sens… Samsung Mobile Mitigation only Fix from $1,9502017-02-01 CRITICAL 9.8 CVE-2016-9420 MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "… Merge System after 1.8.7 Fix from $2,3002017-01-31 HIGH 7.5 CVE-2016-9249 An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to r… Big Ip Local Traffic Manager Mitigation only Fix from $1,9502017-01-31 HIGH 8.8 CVE-2016-6266EPSS 8% ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote aut… Smart Protection Server Patch available Fix from $1,9502017-01-30 HIGH 8.8 CVE-2016-6267EPSS 55% SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated … Smart Protection Server Patch available Fix from $1,9502017-01-30 MEDIUM 5.3 CVE-2016-2516EPSS 11% NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the sam… Ntp after 4.2.8 Fix from $1,6002017-01-30 MEDIUM 5.3 CVE-2016-2517EPSS 8% NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging kno… Ntp after 4.2.8 Fix from $1,6002017-01-30 HIGH 7.5 CVE-2016-9939 Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on th… Debian Linux Patch available Fix from $1,9502017-01-30 MEDIUM 5.3 CVE-2015-8138EPSS 7% NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp se… Ntp after 4.2.8 Fix from $1,6002017-01-30 CRITICAL 9.8 CVE-2016-10176EPSS 72% The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This… Wnr2000v5 Firmware after 1.0.0.34 Fix from $2,3002017-01-30 HIGH 8.4 CVE-2017-3316EPSS 6% Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox… Vm Virtualbox Patch available Fix from $1,9502017-01-27 MEDIUM 6.5 CVE-2017-3273 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.34 and earlier … MySQL after 5.7.16 Fix from $1,6002017-01-27 HIGH 7.8 CVE-2016-9795 The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance f… Ca Workload Automation Ae Mitigation only Fix from $1,9502017-01-27 MEDIUM 5.9 CVE-2017-3242 Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manager). Supported versions that … Vm Server Patch available Fix from $1,6002017-01-27 MEDIUM 6.5 CVE-2017-3256 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.7.16 and … MySQL after 5.7.16 Fix from $1,6002017-01-27 MEDIUM 6.5 CVE-2017-3258 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier,… MySQL 5.5.54 / 10.0.29+ Fix from $1,6002017-01-27 MEDIUM 6.0 CVE-2016-10024 Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction s… Xenserver after 4.8.0 Fix from $1,6002017-01-26 MEDIUM 5.5 CVE-2016-9317EPSS 6% The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via… Libgd after 2.2.3 Fix from $1,6002017-01-26 MEDIUM 5.8 CVE-2017-3800 A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, re… Email Security Appliance Mitigation only Fix from $1,6002017-01-26 HIGH 7.5 CVE-2017-5371 Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted … Adaptive Server Enterprise No fix yet Fix from $1,9502017-01-23 CRITICAL 9.8 CVE-2016-6603EPSS 49% ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. Webnms Framework No fix yet Fix from $2,3002017-01-23 HIGH 7.9 CVE-2016-9379 The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or de… Xenserver Patch available Fix from $1,9502017-01-23 HIGH 7.5 CVE-2016-9380 The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or d… Xenserver Patch available Fix from $1,9502017-01-23 HIGH 8.8 CVE-2016-9383 Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, c… Xenserver Patch available Fix from $1,9502017-01-23 MEDIUM 6.0 CVE-2016-9385 The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of servic… Xenserver Patch available Fix from $1,6002017-01-23 HIGH 7.5 CVE-2016-4793 The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. Cakephp after 3.2.4 Fix from $1,9502017-01-23 HIGH 7.5 CVE-2016-5119 The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check r… Keepass after 2.33 Fix from $1,9502017-01-23 MEDIUM 5.9 CVE-2014-9754 The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (thro… Multichannel Vpn Router 300 Firmware No fix yet Fix from $1,6002017-01-20 HIGH 7.5 CVE-2014-9755 The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (thro… Multichannel Vpn Router 300 Firmware No fix yet Fix from $1,9502017-01-20