Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.9
CVE-2017-8582EPSS 8%

HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gol…

Patch available
Fix from $1,600 2017-07-11
Windows 10 MEDIUM 6.5
CVE-2017-8592EPSS 8%

Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows …

Patch available
Fix from $1,600 2017-07-11
Prime Network MEDIUM 5.5
CVE-2017-6726

A vulnerability in the CLI of the Cisco Prime Network Gateway could allow an authenticated, local attacker to retrieve system process information, wh…

Mitigation only
Fix from $1,600 2017-07-10
Wide Area Application Services MEDIUM 5.3
CVE-2017-6730

A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker t…

Mitigation only
Fix from $1,600 2017-07-10
PHP HIGH 7.5
CVE-2017-11145

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by atta…

Fix: after 5.6.30
Fix from $1,950 2017-07-10
X Pack MEDIUM 6.5
CVE-2017-8442

Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration infor…

Fix: after 5.4.3
Fix from $1,600 2017-07-07
Node.js HIGH 7.5
CVE-2017-1000381

The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given inp…

Fix: 4.8.4 / 6.11.1+
Fix from $1,950 2017-07-07
Android MEDIUM 5.5
CVE-2017-0326

An information disclosure vulnerability in the NVIDIA Video Driver due to an out-of-bounds read function in the Tegra Display Controller driver could…

Mitigation only
Fix from $1,600 2017-07-07
Marp MEDIUM 5.3
CVE-2017-2239

Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript.

Mitigation only
Fix from $1,600 2017-07-07
Rsa Archer Egrc MEDIUM 6.5
CVE-2017-4999

EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an authorization bypass through user-controlled key vulnerability …

Mitigation only
Fix from $1,600 2017-07-07
Android MEDIUM 5.5
CVE-2017-0698

A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35467…

No fix yet
Fix from $1,600 2017-07-06
Android MEDIUM 5.5
CVE-2017-0699

A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36490…

No fix yet
Fix from $1,600 2017-07-06
Android MEDIUM 5.5
CVE-2017-0708

A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

No fix yet
Fix from $1,600 2017-07-06
Android MEDIUM 5.5
CVE-2017-0668

A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Andr…

No fix yet
Fix from $1,600 2017-07-06
Android MEDIUM 5.5
CVE-2017-0669

A information disclosure vulnerability in the Android framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34114752.

No fix yet
Fix from $1,600 2017-07-06
Ultra Services Framework CRITICAL 9.8
CVE-2017-6708

A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unaut…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Ultra Services Framework CRITICAL 9.8
CVE-2017-6709

A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Puppet Enterprise HIGH 7.5
CVE-2017-2294

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.…

Fix: after 2016.4.3
Fix from $1,950 2017-07-05
Linux Kernel MEDIUM 6.5
CVE-2017-10911

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive informa…

Fix: after 4.11.7
Fix from $1,600 2017-07-05
Xen HIGH 7.5
CVE-2017-10916

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU)…

Mitigation only
Fix from $1,950 2017-07-05
Hg100r Firmware CRITICAL 9.8
CVE-2017-7317

An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin.

No fix yet
Fix from $2,300 2017-07-04
Prime Collaboration Provisioning MEDIUM 5.5
CVE-2017-6705

A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitiv…

Mitigation only
Fix from $1,600 2017-07-04
Prime Collaboration Provisioning MEDIUM 5.1
CVE-2017-6706

A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire…

Mitigation only
Fix from $1,600 2017-07-04
Oncommand System Manager HIGH 8.1
CVE-2016-5045

NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.

Mitigation only
Fix from $1,950 2017-07-03
Tor HIGH 7.5
CVE-2017-0377

Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote a…

Patch available
Fix from $1,950 2017-07-02
Kibana MEDIUM 6.5
CVE-2017-8443

In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initial…

Fix: after 5.4.2
Fix from $1,600 2017-06-30
Gecko Lite Managed Switch Firmware MEDIUM 5.3
CVE-2017-6040

An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive informa…

Fix: after 2.0.00
Fix from $1,600 2017-06-30
Airlink Raven Xe Firmware HIGH 7.5
CVE-2017-6046

An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT,…

Mitigation only
Fix from $1,950 2017-06-30
1763 L16awa Series A CRITICAL 9.8
CVE-2017-7899

An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series …

Fix: after 16.000
Fix from $2,300 2017-06-30
Piwigo HIGH 7.5
CVE-2017-10679

Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL …

Fix: after 2.9.1
Fix from $1,950 2017-06-29