Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Threat Discovery Appliance HIGH 7.3
CVE-2016-8588

The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Change And Configuration Management Database HIGH 8.8
CVE-2015-0104EPSS 7%

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 a…

Patch available
Fix from $1,950 2017-04-24
Wave HIGH 8.1
CVE-2016-1518

The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle…

Fix: after 1.0.1.26
Fix from $1,950 2017-04-21
Android HIGH 8.8
CVE-2016-2433

The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in th…

Fix: after 6.0.1
Fix from $1,950 2017-04-21
Moodle MEDIUM 6.5
CVE-2016-3729

The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated…

Mitigation only
Fix from $1,600 2017-04-20
Line HIGH 8.1
CVE-2016-4850

LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.

Fix: after 4.8.2.1125
Fix from $1,950 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6331

ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restri…

Fix: after 1.23.14
Fix from $1,950 2017-04-20
Mediawiki MEDIUM 6.5
CVE-2016-6336

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intend…

Fix: after 1.23.14
Fix from $1,600 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6337

MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights …

Patch available
Fix from $1,950 2017-04-20
Enterprise Virtualization MEDIUM 6.8
CVE-2016-6338

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…

No fix yet
Fix from $1,600 2017-04-20
Sudo HIGH 7.0
CVE-2016-7032

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls th…

Mitigation only
Fix from $1,950 2017-04-14
Galaxy S6 Firmware MEDIUM 6.8
CVE-2016-4030

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I919…

No fix yet
Fix from $1,600 2017-04-13
Galaxy S6 Firmware MEDIUM 6.8
CVE-2016-4031

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I919…

No fix yet
Fix from $1,600 2017-04-13
Spectrum Sdc HIGH 8.8
CVE-2015-8284

SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.

No fix yet
Fix from $1,950 2017-04-13
Jetty CRITICAL 9.8
CVE-2016-4800EPSS 6%

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected res…

Patch available
Fix from $2,300 2017-04-13
Hana CRITICAL 9.8
CVE-2016-6143

SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

Mitigation only
Fix from $2,300 2017-04-13
A Blog Cms MEDIUM 6.5
CVE-2016-1178

The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive …

Fix: after 2.6.0.1
Fix from $1,600 2017-04-12
Cdh HIGH 7.5
CVE-2016-6605

Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

Mitigation only
Fix from $1,950 2017-04-10
Edoc Libraries MEDIUM 5.5
CVE-2015-8275

LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files.

Mitigation only
Fix from $1,600 2017-04-10
Lightify Home HIGH 7.5
CVE-2016-5054

OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.

Fix: after 1.6.1
Fix from $1,950 2017-04-10
Lightify Pro HIGH 7.5
CVE-2016-5058

OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.

No fix yet
Fix from $1,950 2017-04-10
Proxygen HIGH 7.5
CVE-2015-7263

The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host…

Fix: after 0.32.0
Fix from $1,950 2017-04-10
Proxygen HIGH 7.5
CVE-2015-7265

Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL c…

Fix: after 0.32.0
Fix from $1,950 2017-04-10
Lg CRITICAL 9.8
CVE-2014-3928

Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.

Patch available
Fix from $2,300 2017-04-03
Lg HIGH 7.5
CVE-2014-3929

The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote at…

Patch available
Fix from $1,950 2017-04-03
Lg HIGH 7.5
CVE-2014-3930

lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain I…

Mitigation only
Fix from $1,950 2017-04-03
Hisuite HIGH 7.8
CVE-2016-8274

Huawei PC client software HiSuite 4.0.5.300_OVE has a dynamic link library (DLL) hijack vulnerability; an attacker can make the system load malicious…

Mitigation only
Fix from $1,950 2017-04-02
Mate S Firmware HIGH 7.1
CVE-2016-8791

Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before…

Mitigation only
Fix from $1,950 2017-04-02
Mate S Firmware HIGH 7.1
CVE-2016-8792

Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before…

Mitigation only
Fix from $1,950 2017-04-02
Mate S Firmware MEDIUM 6.7
CVE-2016-8793

Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before…

Mitigation only
Fix from $1,600 2017-04-02